Package Health

pixelmairie/sulu-eventbundle

The package includes a useful README, release notes, security scanning, and a recent repository update. Its small audience and limited recent activity leave less evidence of sustained maintenance, while the workflow uses four unpinned actions.

Latest 2.7.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package has existed for over three years and released twice in the past 12 months, but the roughly five-month median interval indicates a modest maintenance cadence.

Repo bus factorcaution

All recent commits came from one contributor, creating concentration risk; organization ownership provides some capacity to hand maintenance off but does not demonstrate a second active contributor.

Repo commit activitycaution

Only one commit was recorded in the past three months, showing limited recent implementation activity despite the recent release.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations less transparent for a package integrated into Sulu applications.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers or audit findings, but all four action references are unpinned, weakening build reproducibility and supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Pixel Mairie

Direct Dependencies

DependencyLast ReleaseScore
sulu/sulu
Version ^2.6
—
—
symfony/config
Version ^5.0 || ^6.0
—
—
symfony/http-kernel
Version ^5.0 || ^6.0
—
—
symfony/http-foundation
Version ^5.0 || ^6.0
—
—
symfony/framework-bundle
Version ^5.0 || ^6.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform