Package Health

cowegis/cowegis-api-bundle

This is a usable, transparently sourced Symfony bundle with a stable 2.1.0 release, an active non-archived organization-owned repository, explicit licensing, build tooling, Dependabot scanning, and no install-time scripts or dangerous workflow patterns. However, maintenance evidence is mixed: the package has only three releases over roughly two years, no commits or active maintainers in the last three months, no detected tests, no security policy, and a workflow without top-level token permissions. These concerns warrant caution and monitoring before adopting it as a critical dependency, but they do not indicate that the package is unfit to use.

Latest 2.1.0PackagistPackagist

66%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Package scaffoldingcaution

The artifact has a README and changelog, but neither the artifact nor the linked repository is reported to contain tests. The missing tests reduce verification transparency, while the changelog and documentation provide partial compensation.

Release historycaution

The package is about 716 days old with only three releases and a median release interval of about 358 days, although two releases occurred in the last 12 months and version 2.1.0 was released recently. This indicates a relatively slow but not clearly abandoned release cadence.

Repo commit activitycaution

There were zero commits and zero active maintainers during the last three months. Although a recent release and push provide some counterevidence, the absence of recent commit activity is a material maintenance concern.

Repo issue activitycaution

There are no open issues and one open pull request, but no issues or pull requests were merged during the last month. The lack of reported issue backlog is positive, while recent collaboration evidence is limited.

Repo popularitycaution

The repository has zero stars and forks and only one watcher. This offers little community validation, but popularity is supporting evidence rather than a decisive health criterion for a small specialized bundle.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

David Molineus

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.0
symfony/config
Version ^6.0 || ^7.0 || ^8.2
beberlei/assert
Version ^3.2
symfony/routing
Version ^6.0 || ^7.0 || ^8.2
psr/http-factory
Version ^1.0

Weekly Downloads

Info

Last Published
19 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform