Package Health

ergonode/importer

The package has a clear license, tests, organization ownership, and a matching repository, which support dependable use. Its maintenance and security automation evidence is limited, so pinning this older release carries ongoing compatibility risk.

Latest 1.3.0PackagistPackagist

54%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Release historydanger

The package has 47 releases and historically released about every 13 days, but it has had no releases in nearly 4 years and 8 months. The long publishing gap materially raises abandonment and compatibility risk.

Repo commit activitydanger

There were no commits and no active maintainers in the last 3 months, consistent with the last repository push being in January 2022. This is strong evidence of stopped maintenance.

Dependency profilecaution

Sixteen runtime dependencies create a relatively broad dependency surface for a framework bundle, increasing compatibility exposure, but the signal does not show that the dependencies are unsafe or abandoned.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. That is a security-hygiene gap, although it does not by itself show that the release is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
ramsey/uuid
Version ^3.8
—
—
ergonode/api
Version ^1.3.0
—
—
symfony/form
Version ^4.4.11|^5.3
—
—
doctrine/dbal
Version ^2.13
—
—
ergonode/core
Version ^1.3.0
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform