Package Health

nucleos/sitemap-bundle

The MIT license, tests, README, changelog, and release notes make the package transparent and maintainable in structure. Its replacement is explicitly identified, so new projects should use nucleos/seo-bundle instead.

Latest 4.4.0PackagistPackagist

12%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

40

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned and names nucleos/seo-bundle as its replacement. This is a direct indication that new dependencies should not be placed on this package.

Release historydanger

The package has had no releases in the last 12 months, and its latest release was on September 18, 2022. This supports the abandonment concern rather than offsetting it.

Repo commit activitydanger

There were no commits and no active maintainers in the last three months. This is consistent with the archived and abandoned project state.

Repository archiveddanger

The linked repository is archived, with its last push on September 18, 2022. Archived source means ongoing maintenance and fixes should not be expected.

Workflow auditcaution

Both workflows were analyzed without high-confidence findings or untrusted-code sinks, but both action references are unpinned. That is a minor reproducibility and supply-chain hygiene concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Christian Gripp

Direct Dependencies

DependencyLast ReleaseScore
psr/cache
Version ^1.0 || ^2.0 || ^3.0
—
—
symfony/config
Version ^5.4 || ^6.0
—
—
symfony/routing
Version ^5.4 || ^6.0
—
—
psr/simple-cache
Version ^1.0 || ^2.0 || ^3.0
—
—
symfony/http-kernel
Version ^5.4 || ^6.0
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform