Package Health

azine/emailupdateconfirmation-bundle

This is a generally healthy release to depend on: it has a stable major version, a long release history, a current release, an unarchived linked repository, a complete-looking artifact with tests, README, changelog, and license, and no install-time lifecycle scripts. The main concerns are the small repository audience, only one recent active contributor with all recent commits, no declared security policy or automated security scanning, and a publish workflow with top-level write permissions. These are meaningful supply-chain and continuity gaps, but they are partly offset by recent issue and pull-request resolution, clear package/repository alignment, and a well-structured tested source tree.

Latest 2.0.1PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dependency profilecaution

The package declares 21 runtime dependencies, including substantial Symfony, Doctrine, and FOSUserBundle components; this is reasonable for its framework-bundle role but increases compatibility and transitive-maintenance exposure.

Maintainerscaution

Only one registry account, Azine IT Services AG, has publish access. The linked repository owner is an individual account rather than an organization, so there is limited observable publishing redundancy.

Project backingcaution

The repository is owned by the user account 'azine' rather than an organization, so the single-contributor and single-publisher findings are not visibly compensated by organization-level handoff capacity.

Repo bus factorcaution

One contributor made all commits in the last three months, with a 100% share, creating a genuine continuity and abandonment risk; no organization backing is shown to compensate for this concentration.

Repo commit activitycaution

Only one commit was recorded in the last three months, which shows some recent activity but a low maintenance cadence for a package with ongoing framework dependencies.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Azine IT Services AG

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.14
doctrine/orm
Version ^3.6
symfony/mime
Version ^7.4
symfony/yaml
Version ^7.4
symfony/config
Version ^7.4

Weekly Downloads

Info

Last Published
14 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform