Package Health

dreadnip/smart-dto-bundle

The package includes tests, a README, an MIT license, and release notes for this version. Its workflow uses six unpinned actions, and the project has no security policy, leaving maintenance and build hygiene concerns.

Latest v0.2PackagistPackagist

56%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The latest release was in October 2022, nearly four years ago, with no releases in the last 12 months. This is strong evidence of stalled maintenance for a dependency.

Maintainerscaution

Only one registry account can publish releases, which creates a thin publishing base. The repository is also owned by an individual, so no organizational backing compensates for that concentration.

Repo popularitycaution

The repository has zero stars and zero forks, with one watcher. Popularity is not required for health, but these numbers provide little supporting evidence of adoption or community resilience.

Security policycaution

The repository has no security policy. This weakens disclosure transparency, although it is not by itself evidence that the package is unsafe.

Workflow auditcaution

The workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, but all six action references are unpinned. That leaves avoidable build-supply-chain drift despite the otherwise clean audit.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Sander De la Marche

Direct Dependencies

DependencyLast ReleaseScore
doctrine/orm
Version ^2.11
symfony/config
Version ^5.2 || ^6.0
symfony/http-kernel
Version ^6.0
symfony/property-info
Version ^6.0
symfony/property-access
Version ^6.0

Weekly Downloads

Info

Last Published
3 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform