Package Health

coolms/dtmpl-bundle

It has solid tests, documentation, a matching repository, and recent activity from two contributors. The prerelease status, short project history, missing security policy, and unpinned workflow actions warrant extra care before production adoption.

Latest v2.0.0-alpha2PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The package is only 38 days old with three releases and a median interval of about 14 days. This shows recent activity but provides limited evidence of long-term maintenance.

Repo bus factorcaution

Two contributors are active, but one accounts for about 79% of recent commits. The second contributor provides some continuity, while the concentration still creates moderate succession risk.

Repo popularitycaution

The repository has no stars, forks, or watchers. For a package only 38 days old this is limited supporting evidence rather than a decisive health problem.

Repo toolingcaution

Composer build tooling is present, but no security scanning tool was detected. The missing scanning coverage is a minor transparency and maintenance gap.

Security policycaution

The repository has no security policy. This does not show unsafe code, but it leaves vulnerability-reporting and response expectations undocumented.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Dmitry Popov

Direct Dependencies

DependencyLast ReleaseScore
coolms/dtmpl
Version ^2.1
—
—
symfony/config
Version ^8.0
—
—
symfony/http-kernel
Version ^8.0
—
—
symfony/dependency-injection
Version ^8.0
—
—

Weekly Downloads

Info

Last Published
22 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform