Package Health

nelmio/api-doc-bundle

Healthy and suitable to depend on. It has a long release history, frequent recent releases, active multi-contributor maintenance, and strong repository hygiene; workflow permissions and contributor concentration deserve routine review but do not outweigh the evidence of ongoing support.

Latest v5.12.2PackagistPackagist

91%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Dangerous workflowscaution

Two workflows use pull_request_target, which warrants review because that trigger can run with elevated repository context; however, no untrusted checkouts or script-injection patterns were detected.

Token permissionscaution

Three workflows grant top-level write permissions and five omit top-level permissions, while no analyzed workflow declares read-only permissions. This is a workflow-hardening gap, although it does not indicate abandonment.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Symfony Community

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0 || ^2.0 || ^3.0
—
—
psr/cache
Version ^1.0 || ^2.0 || ^3.0
—
—
psr/container
Version ^1.0 || ^2.0
—
—
symfony/config
Version ^6.4 || ^7.2 || ^8.0
—
—
symfony/console
Version ^6.4 || ^7.2 || ^8.0
—
—

Weekly Downloads

Info

Last Published
13 days ago
Created
14 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform