Documentation and test coverage make integration easier. The organization-backed project is not archived or deprecated, but recent commit activity is currently absent, so ongoing maintenance deserves attention.
68%
Total Score
75
100
88
83
The package has existed for about 8 years with 48 releases, but only one release in the past 12 months. This shows maturity with a currently slow release pace.
There were zero commits and zero active maintainers in the past three months. Although a release was published recently, the absence of recent commit activity leaves current maintenance capacity uncertain.
The repository uses Make and Composer, but no security-scanning tools were detected. The missing scanning automation is a modest hygiene gap rather than evidence of abandonment.
The repository has no security policy. This reduces transparency for reporting and handling vulnerabilities, though it is not by itself a severe adoption risk.
No GitHub Actions workflows were present, so there were no workflow risks to assess. This also means there is no observed workflow-based build or security automation.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hanaboso/user-bundle Version ^1.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.