Package Health

ongr/settings-bundle

The release is documented, tested, licensed, and backed by an organization. Its ecosystem and security hygiene are dated, so new adoption should be avoided unless compatibility requires this exact bundle.

Latest v1.0.0PackagistPackagist

15%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no replacement supplied. Package-level abandonment is a severe dependency and maintenance risk.

Release historydanger

The package has had no releases in nearly 10 years; its latest release was in October 2016. That strongly indicates the dependency is no longer maintained for current consumers.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and reinforcing abandonment risk.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, while four issues and one pull request remain open. This suggests little ongoing maintenance or response.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a secondary transparency gap alongside the broader maintenance concerns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

ONGR team

Direct Dependencies

DependencyLast ReleaseScore
doctrine/cache
Version ~1.4
—
—
symfony/symfony
Version ~2.7|~3.0
—
—
ongr/cookies-bundle
Version ~1.0
—
—
ongr/elasticsearch-bundle
Version ~1.2.4
—
—
ongr/filter-manager-bundle
Version ~1.0
—
—

Weekly Downloads

Info

Last Published
9 years ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform