Package Health

linkorb/spicedb-bundle

This release is usable but warrants caution. It is a stable, non-deprecated package with a clear MIT declaration, matching repository, tests, and an organization-backed source repository, and it was released very recently. However, the repository shows no commits or active maintainers in the last three months, only one release in the last 12 months, negligible adoption signals, no security policy or security scanning, and no changelog. The repository README also identifies it as a read-only subtree whose issues should go to an upstream project, so maintenance may depend on activity outside this repository. Overall, the package is not evidently abandoned or unfit, but its thin direct maintenance and security transparency make it a moderate-risk dependency.

Latest v4.123.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health checks

Dependency profilecaution

The package declares 8 runtime dependencies, including its client library and several Symfony components; this is a meaningful dependency surface but is reasonable for a Symfony integration bundle.

Release historycaution

The package has existed for about 3 years and 5 months with 9 releases, but only 1 release in the last 12 months indicates relatively slow release activity despite the current release being recent.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers during the last 3 months. Although the latest release and push are recent, the lack of recent development activity raises maintenance and abandonment concerns.

Repo issue activitycaution

There are no open issues or pull requests and no issue or pull-request activity in the last month; this is neutral for a small read-only subtree but provides little evidence of an active support community.

Repo popularitycaution

The repository has 0 stars and 2 forks, indicating very limited visible adoption; popularity is supporting evidence rather than a standalone disqualifier, but it reduces confidence in community resilience.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

LinkORB

Direct Dependencies

DependencyLast ReleaseScore
symfony/yaml
Version ^4.4|^5.4|^6.4|^7.2
symfony/config
Version ^4.4|^5.4|^6.4|^7.2
linkorb/spicedb-php
Version ^1.1
symfony/http-kernel
Version ^4.4|^5.4|^6.4|^7.2
symfony/security-core
Version ^4.4|^5.4|^6.4|^7.2

Weekly Downloads

Info

Last Published
10 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform