Package Health

friendsofsymfony/comment-bundle

Documentation, tests, release notes, and an MIT license provide solid adoption support. The repository remains active in structure but lacks security scanning and has five unpinned workflow actions.

Latest v3.0.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historydanger

The package has 32 releases over more than 14 years, but none in the last six years; this is a substantial maintenance concern for a framework bundle.

Repo commit activitydanger

No commits and no active maintainers were recorded in the last three months, reinforcing the concern raised by the absence of recent releases.

Dependency profilecaution

Sixteen runtime dependencies create a relatively broad dependency surface for a Symfony bundle, increasing compatibility and maintenance burden.

Repo issue activitycaution

There are 54 open issues and no issue or pull request activity in the last month, consistent with a project receiving little current attention.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tooling was detected; this is a modest repository hygiene gap rather than evidence of unfitness.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Tim Nagel
Alexander Mols
FriendsOfSymfony Community

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ~2.0|~3.0
—
—
symfony/form
Version ~3.4|^4.3
—
—
symfony/yaml
Version ~3.4|^4.3
—
—
symfony/asset
Version ~3.4|^4.3
—
—
symfony/routing
Version ~3.4|^4.3
—
—

Weekly Downloads

Info

Last Published
6 years ago
Created
14 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform