Package Health

metamodels/bundle_attributes

Its stable major version, organization backing, and clear license support continued use. The three-file project, no tests, no security policy, and 17 months without commits leave maintenance and transparency concerns.

Latest 2.3.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Package file treecaution

The artifact and repository each contain only three files, including just a short README and composer.json; this provides little visible project documentation or development context.

Release historycaution

The package has existed since 2014 with eight releases, but it had no releases in the last 12 months and its latest release was about 17 months ago, indicating slow or paused maintenance.

Repo commit activitycaution

The repository recorded no commits and no active maintainers in the last three months, consistent with the roughly 17-month gap since the last push and raising abandonment concerns.

Repo popularitycaution

Four stars and two forks show limited adoption evidence, though popularity is supporting context rather than a health verdict and does not outweigh the organization backing.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tooling was detected, leaving a modest repository hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Christian Schiffler
Stefan Heimes

Direct Dependencies

DependencyLast ReleaseScore
metamodels/attribute_color
Version ^2.3
—
—
metamodels/attribute_rating
Version ^2.3
—
—
metamodels/attribute_country
Version ^2.3
—
—
metamodels/attribute_decimal
Version ^2.3
—
—
metamodels/attribute_numeric
Version ^2.3
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform