Tests, licensing, and regular releases provide useful support. Organization backing helps, but the recent lack of commits and unclear package-to-repository connection warrant checking maintenance before adoption.
68%
Total Score
83
100
81
75
The repository recorded zero commits and zero active maintainers in the last three months. The recent release and push provide some compensation, but current development activity is still unclear.
The repository name does not match the package name and its README does not mention the package. The README identifies it as a subtree split, which partly explains the mismatch but leaves package ownership less explicit.
Composer build tooling is present, but no security-scanning tooling was detected, leaving a modest transparency and maintenance gap.
The linked repository has no security policy, reducing clarity about how vulnerabilities are reported and handled.
This is a regular, non-prerelease release, although the package remains below a stable major version, which signals some ongoing API-evolution risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
enhavo/api-bundle Version ^0.15 | — | — |
enhavo/app-bundle Version ^0.15 | — | — |
enhavo/resource-bundle Version ^0.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.