Package Health

evaneos/burrow-bundle

It has a clear README, tests, MIT licensing, and a matching Evaneos repository. The main concern is that releases and commits stopped nearly four years ago, while the repository has no security scanning or security policy.

Latest v1.3.1PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The latest release was published nearly four years ago, with no releases in the previous 12 months. This indicates substantially slowed maintenance for a package intended as a reusable library.

Repo commit activitycaution

There were no commits and no active maintainers during the last three months. Combined with the old last release, this is strong evidence of inactive maintenance.

Repo popularitycaution

The repository has only 2 stars and 2 forks, indicating limited adoption and external validation. Popularity is supporting evidence rather than a decisive health judgment, so this is a minor concern.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. That leaves a maintenance and oversight gap, though it is not severe on its own.

Repository archivedcaution

The linked repository is not archived, so the project remains administratively available. However, its last push was nearly four years ago, consistent with the maintenance concern shown by release history.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Quentin

Direct Dependencies

DependencyLast ReleaseScore
evaneos/burrow
Version ^4.0
—
—
symfony/http-kernel
Version ^3.0|^4.0
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform