Package Health

benmacha/audit-bundle

The codebase is documented, tested, licensed, and supported by dependency and security tooling. Pin this exact version only if you can accept a one-person project with quiet recent activity and loosely pinned CI actions.

Latest 0.1.0PackagistPackagist

61%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Dependency profilecaution

The package declares 19 runtime dependencies across Symfony, Doctrine, Twig, and related components, creating a relatively broad compatibility and maintenance surface for a 0.1.0 bundle.

Lifecycle scriptscaution

Composer post-install and post-update scripts execute package-defined actions during dependency operations, adding an install-time behavior that should be understood before adoption.

Maintainerscaution

One registry maintainer is consistent with the user-owned repository, but it leaves the project with a thin apparent maintainer base and limited redundancy.

Release historycaution

This is the only release after about 1 year and 1 month, with no releases in the last 12 months, so ongoing maintenance is not yet demonstrated.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months, which is a meaningful maintenance concern for a young package.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ben Mecha

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.0
—
—
doctrine/orm
Version ^2.10|^3.0
—
—
symfony/form
Version ^5.4|^6.0|^7.0
—
—
symfony/yaml
Version ^5.4|^6.0|^7.0
—
—
symfony/cache
Version ^5.4|^6.0|^7.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform