Package Health

ekino/phpstan-sonata

The package has a clear README, tests, release notes, MIT licensing, and an organization-backed repository. Its workflow has no audit findings, but its two actions are unpinned and no security policy is published.

Latest v1.0.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The latest release was in November 2021, with no releases during the last 12 months. The repository was pushed in November 2024, which provides some evidence of later maintenance but does not show ongoing release activity.

Repo commit activitycaution

There were no commits and no active maintainers during the last three months. The repository's November 2024 push partly offsets this, but the current activity still indicates limited ongoing maintenance.

Security policycaution

No security policy is published in the repository. This is a transparency gap, although the package's lack of install scripts and clean workflow audit reduce the practical concern.

Workflow auditcaution

The single workflow was fully analyzed with no audit findings, and it has no untrusted triggers or injection sinks. Both of its action references are unpinned, which is a supply-chain hygiene weakness.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Rémi Marseille

Direct Dependencies

DependencyLast ReleaseScore
phpstan/phpstan
Version ^1.0
—
—
sonata-project/datagrid-bundle
Version ^3.0
—
—
sonata-project/doctrine-orm-admin-bundle
Version ^3.6
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform