Package Health

edrush/extbaser-bundle

The package is small and easy to inspect, with a README, changelog, matching repository, and no install-time scripts. Its old release and inactive repository make compatibility and support uncertain; the GPL declaration also conflicts with the detected MIT license.

Latest v0.1.0PackagistPackagist

36%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

64

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

This is the package's only release, published over 11 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk for a dependency targeting evolving Symfony and TYPO3 ecosystems.

Repo commit activitydanger

The repository recorded no commits or active maintainers in the last 3 months, and its last push was over 8 years ago. This is strong evidence that maintenance has stopped.

Licensecaution

The artifact contains a license file and the repository also has one, so licensing is documented. However, the manifest declares GPL while the detected license is MIT, creating a material licensing ambiguity.

Repo toolingcaution

Composer is used for the build, which fits the package ecosystem, but no security-scanning tooling was found. This is a secondary transparency and maintenance gap beside the much stronger inactivity evidence.

Security policycaution

The linked repository has no security policy. For a small, long-inactive package this reduces clarity about vulnerability reporting and supported versions.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Wolfram Eberius

Direct Dependencies

DependencyLast ReleaseScore
doctrine/orm
Version >=2.3
edrush/extbaser
Version *
symfony/framework-bundle
Version >=2.3

Weekly Downloads

Info

Last Published
11 years ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform