Package Health

pixeldev/sulu-townhallbundle

This is a generally usable and transparently backed package: it has a stable release line, 18 releases over more than four years, five releases in the last 12 months, a recent latest release and repository push, an unarchived organization-owned repository, a substantial source tree, and no install-time scripts or dangerous workflow patterns. The main concerns are that no tests were found in either the artifact or repository, repository commit activity reports zero commits and zero active maintainers over the last three months despite the recent release, and the repository lacks an explicit security policy and top-level workflow token permissions. Dependence is reasonable, but verify current maintenance responsiveness and test coverage before adopting it for a critical system.

Latest 3.1.4PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Package scaffoldingcaution

A substantial README and changelog are present and the repository uses GitHub Releases, but no tests were found in either the package or repository; this leaves an important quality and maintenance gap.

Repo commit activitycaution

The repository reports zero commits and zero active maintainers during the last three months, which raises a maintenance concern; however, the latest release and repository push occurred recently, so this is not by itself evidence of abandonment.

Repo popularitycaution

The repository has zero stars and forks and one watcher. This is weak supporting evidence, but popularity is not decisive and the organization backing and release history provide compensating context.

Security policycaution

No repository security policy was found, reducing transparency about vulnerability reporting and response procedures.

Token permissionscaution

The only workflow lacks top-level token permissions. Although no write permissions were detected, explicit least-privilege declarations would provide stronger workflow security hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Pixel Mairie

Direct Dependencies

DependencyLast ReleaseScore
sulu/sulu
Version ^2.6
sulu/automation-bundle
Version ^2.1
symfony/framework-bundle
Version ^6.0

Weekly Downloads

Info

Last Published
24 days ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform