Package Health

glavweb/data-schema-bundle

This release appears healthy and suitable to depend on: it has a long history since 2018, 49 releases including 9 in the last 12 months, a stable non-prerelease version, active recent repository commits from two contributors, organization backing, and no deprecation or archival indicators. The main reservations are the absence of tests and a changelog, no repository security policy or security-scanning tooling, and negligible repository popularity; these reduce transparency and assurance but do not outweigh the strong release and maintenance evidence.

Latest 3.1.2PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Dependency profilecaution

The package declares 11 runtime dependencies, including substantial Symfony and Doctrine components; this increases integration and transitive-maintenance surface, but is consistent with a Symfony data-schema bundle.

Package scaffoldingcaution

A substantive README is present, but neither the package artifact nor repository contains tests or a changelog. These are genuine transparency and verification gaps, although GitHub Releases are used as a partial release-management signal.

Repo popularitycaution

The repository has 0 stars and 0 forks, providing little community validation. This is supporting evidence only and does not outweigh the observed release cadence and recent activity.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tooling is detected. The missing scanning automation lowers assurance, while the absence of build tooling would have been a more serious concern and is not present.

Security policycaution

The linked repository has no security policy, leaving vulnerability-reporting and disclosure expectations undocumented. This is a transparency gap, not evidence that the package is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

nilov
GLAVWEB Community

Direct Dependencies

DependencyLast ReleaseScore
doctrine/orm
Version ^3.3
—
—
symfony/yaml
Version ^8.0
—
—
symfony/config
Version ^8.0
—
—
symfony/finder
Version ^8.0
—
—
symfony/twig-bridge
Version ^8.0
—
—

Weekly Downloads

Info

Last Published
19 days ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform