Package Health

neimheadh/sonata-annotation-bundle

The source includes tests, a changelog, and matching MIT licensing, while the package has no install-time scripts. Its limited issue activity and absent security policy provide little additional support for long-term maintenance.

Latest 2.1.0PackagistPackagist

43%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

90

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The package has had no release in about three years, despite 18 releases overall. This is a meaningful abandonment concern, although the stable 2.1.0 version and repository remaining unarchived provide limited compensation.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. This substantially weakens evidence of ongoing maintenance.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, with one issue still open. The low activity offers little evidence that problems are being actively addressed.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations and response guidance undocumented. This is a transparency and maintenance gap, though not severe by itself.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Marko Kunic
Mathieu Wambre

Direct Dependencies

DependencyLast ReleaseScore
symfony/config
Version ^5.4 || ^6.0
—
—
symfony/finder
Version ^5.4 || ^6.0
—
—
symfony/http-kernel
Version ^5.4 || ^6.0
—
—
doctrine/annotations
Version ^1.7
—
—
sonata-project/admin-bundle
Version ^4.0
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform