Package Health

patchlevel/event-sourcing-dashboard-bundle

This release appears suitable to depend on, with a clear MIT license, a matching and actively updated source repository, tests, substantial documentation, build tooling, recent commit and pull-request activity, and no deprecation or dangerous workflow findings. The main reservations are that the package is young with only three releases, all recent repository commits come from one contributor, and the repository lacks an explicit security policy and top-level GitHub Actions token permissions; these are meaningful hygiene and continuity concerns, but organizational ownership and recent activity reduce the abandonment risk.

Latest 1.0.0PackagistPackagist

76%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Release historycaution

The package is only 79 days old and has three releases, with a median release interval of about 79 days; this is limited evidence of long-term stability, though releases have continued through the assessment period.

Repo bus factorcaution

All nine recent commits came from one contributor, giving the repository a concentrated bus factor. Organizational ownership provides some handoff capacity, but no second active contributor is shown in this signal.

Repo toolingcaution

The repository uses Make and Composer build tooling, but no security-scanning tools were detected; the missing automated security coverage is a modest hygiene gap.

Security policycaution

No repository security policy was found. This reduces transparency around vulnerability reporting and response expectations, although it does not by itself indicate abandonment.

Token permissionscaution

All 10 workflows lack top-level token permission declarations. Although none declares top-level write permissions, explicitly constraining workflow tokens would provide stronger CI security hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Daniel Badura
David Badura

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.20.0
—
—
symfony/asset
Version ^5.4.33 || ^6.4.1 || ^7.0.1 || ^8.0.0
—
—
symfony/config
Version ^5.4.31 || ^6.4.0 || ^7.0.0 || ^8.0.0
—
—
symfony/routing
Version ^5.4.33 || ^6.4.1 || ^7.0.1 || ^8.0.0
—
—
symfony/var-dumper
Version ^5.4.29 || ^6.4.0 || ^7.0.0 || ^8.0.0
—
—

Weekly Downloads

Info

Last Published
20 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform