Package Health

bitbag/product-bundle-plugin

Organization backing, a substantial README, tests, and a declared MIT license provide useful support. The missing security policy and weak workflow pinning leave maintenance and build-integrity gaps that deserve attention.

Latest v3.0.1PackagistPackagist

67%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

90

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The package has existed for about 6 years with 17 releases, but only 1 release in the last 12 months; the recent June 2026 release partly offsets the slow cadence.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months, indicating currently limited visible maintenance despite the recent release.

Security policycaution

The linked repository has no security policy, reducing transparency for reporting and handling vulnerabilities; no provided signal compensates for that gap.

Workflow auditcaution

The audit covered both workflows and found no untrusted checkouts or script injection, but all 12 action references are unpinned. The cache-poisoning findings are low-confidence hygiene warnings and do not independently establish a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
dompdf/dompdf
Version ^2.0
—
—
sylius/sylius
Version ^2.0.0
—
—
symfony/webpack-encore-bundle
Version ^2.1
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform