Package Health

movingimage/vm6-data-provider-bundle

The license needs clarification, and the linked repository does not identify this package in its README. Organization ownership and no install scripts provide limited reassurance.

Latest v1.5.1PackagistPackagist

18%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

40

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Using this package? Scan for Free

Health Score Breakdown

Release historydanger

The package has had no release in more than nine years: all five releases were published in May 2017, with none in the last 12 months. This is strong evidence of abandonment for a dependency.

Repository archiveddanger

The repository is not formally archived, but it was last pushed in May 2017, matching the stale registry history. That lack of activity offers little practical maintenance assurance.

Licensecaution

The manifest declares a Proprietary license while the repository license file is recognized as BSD-3-Clause. This mismatch needs clarification before adoption, even though a repository license exists.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention this package, so the source-package relationship is not clearly established. The organization owner is a partial compensating signal, but not enough to remove the concern.

Security policycaution

The repository has no security policy. For an old, unmaintained dependency, the absence of a documented vulnerability-reporting path adds transparency risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Robert Szeker

Direct Dependencies

DependencyLast ReleaseScore
symfony/framework-bundle
Version ^2.7 || ^3.0
—
—
movingimage/vm6-api-bundle
Version dev-master
—
—
movingimage/data-provider-vm6
Version ^1.5
—
—

Weekly Downloads

Info

Last Published
9 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform