Package Health

grinway/service-bundle

The package includes tests, a changelog, a matching repository, and consistent MIT licensing. Maintenance has slowed recently, while one maintainer, no security scanning, and mostly unpinned workflow actions add ongoing risk.

Latest 5.2.0PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Maintainerscaution

Only one registry account can publish the package. That is a thin publishing base for a user-owned project, although the release history shows that this maintainer has continued publishing.

Project backingcaution

The repository is owned by a user rather than an organization, so there is no organizational backing to offset the single-maintainer publishing model.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. This suggests maintenance has recently stalled, despite the release on May 5, 2026.

Repo popularitycaution

The repository has zero stars and forks and one watcher. Popularity is not decisive, but these figures provide little supporting evidence of broad adoption or external review.

Repo toolingcaution

Composer is used as the build tool, but no security scanning tools were detected. The missing scanning is a maintenance and transparency gap for a package with 26 runtime dependencies.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Grigory Koblitskiy

Direct Dependencies

DependencyLast ReleaseScore
doctrine/orm
Version ^3.3
symfony/yaml
Version ^7.2|^6
doctrine/dbal
Version ^3.9
nesbot/carbon
Version ^3.8
symfony/asset
Version ^7.2

Weekly Downloads

Info

Last Published
4 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform