Package Health

cyllene-web/docusign-bundle

Repository tests, clear documentation, and a stable MIT license make integration easier. Install and update hooks, no security policy, and an undeclared workflow token scope add maintenance and review overhead.

Latest 5.7.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dependency profilecaution

Nineteen runtime dependencies, including multiple DocuSign, Symfony, and filesystem components, create a relatively broad update and compatibility surface.

Lifecycle scriptscaution

post-install-cmd and post-update-cmd scripts add install-time behavior that deserves review and increases dependency-installation complexity.

Release historycaution

The package has six releases over about 2 years and 11 months, but none in the last 12 months; that suggests a meaningful slowdown for a maintained integration library.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months, which is a direct sign that maintenance has currently stalled.

Security policycaution

The repository has no published security policy, leaving vulnerability-reporting expectations and response guidance unclear.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Grégoire Hébert
Vincent Chalamon

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.1 || ^2.0 || ^3.0
lcobucci/jwt
Version ^3.3.1 || ^4.0
vgrem/php-spo
Version ^2.2
symfony/config
Version ^5.0 || ^6.0
symfony/routing
Version ^5.0 || ^6.0

Weekly Downloads

Info

Last Published
1 year ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform