Package Health

nascom/grumphp-symfony

The focused seven-file package has a usable README and its repository matches the package, but it has no security scanning and one unresolved issue. Its stable version and organization backing help, though ongoing maintenance capacity is unclear.

Latest 2.0.2PackagistPackagist

47%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Licensecaution

No declared license, license file, or repository license file was detected. This is a transparency and adoption concern because downstream users cannot establish clear reuse terms.

Release historycaution

The latest release was published over three years ago, with no releases in the last 12 months and only three releases overall. This indicates a meaningful maintenance concern for a development tool.

Repo commit activitycaution

The repository recorded no commits and had no active maintainers in the last three months. The package is small, but this still leaves current compatibility and maintenance uncertain.

Repo issue activitycaution

One issue remains open, with no issue or pull-request activity in the last month. This is a modest sign of limited project attention rather than evidence of abandonment on its own.

Repo toolingcaution

The repository uses Composer, but no security-scanning tooling was detected. For a small configuration package this is a hygiene gap, though it is partly offset by the limited file tree.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
phpro/grumphp
Version ^1.0
—
—
phpstan/phpstan
Version ^1.8
—
—
squizlabs/php_codesniffer
Version ^3.4
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform