Package Health

coosos/version-workflow-bundle

The package includes tests, documentation, release notes, and no install-time scripts. Its repository has no security policy, minimal adoption, and no recent commits, limiting confidence in ongoing support.

Latest 0.2.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

50

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The latest release was over six years ago, with no releases in the last 12 months. The earlier seven releases were concentrated in a short period, but there is no evidence of continued maintenance.

Repo commit activitydanger

The repository had zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating likely abandonment.

Licensecaution

The manifest declares GPL-3.0, while the artifact license file is detected as LGPL-3.0. The presence of license files is positive, but the declaration mismatch requires legal review.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package. This weakens confidence that the linked repository is the authoritative source rather than an unrelated project repository.

Repo popularitycaution

The repository has one star, zero forks, and zero watchers. Low popularity is not decisive for a small package, but it provides little supporting evidence of active use or community backup.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Rémy Lescallier

Direct Dependencies

DependencyLast ReleaseScore
doctrine/orm
Version ^2.6
—
—
symfony/config
Version ^4.2
—
—
symfony/workflow
Version ^4.2
—
—
symfony/serializer
Version ^4.2
—
—
symfony/http-kernel
Version ^4.2
—
—

Weekly Downloads

Info

Last Published
6 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform