Package Health

fundistadi/postgis-bundle

The repository includes tests, release notes, and clear documentation, while organization ownership provides some continuity. Three workflow actions are unpinned, and the project has no security policy or scanning coverage.

Latest v0.5.1PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The package is only 42 days old, with 7 releases in that period and a very short median interval of about 6 hours 52 minutes. This shows active iteration but provides limited evidence of long-term maturity.

Repo bus factorcaution

One contributor made all 29 commits in the last 3 months. Organization ownership provides some handoff capacity, but the observed maintenance base remains highly concentrated.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. For a dependency package, that reduces supply-chain transparency and gives less evidence of proactive issue detection.

Security policycaution

The repository has no security policy. This is a transparency and vulnerability-reporting gap, although it does not by itself indicate unsafe code.

Version stabilitycaution

Version v0.5.1 is not a stable major release, so its API and behavior may still change. It is not marked as a prerelease, which partly offsets the concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ezekiel Mjema

Direct Dependencies

DependencyLast ReleaseScore
doctrine/orm
Version ^3.5
doctrine/dbal
Version ^4.0
doctrine/doctrine-bundle
Version ^3.0
symfony/framework-bundle
Version ^7.3 || ^8.0

Weekly Downloads

Info

Last Published
1 month ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform