Package Health

plozmun/http-cache-bundle

The MIT license, included tests, changelog, and readable documentation provide a solid starting point. However, this alpha release is more than nine years old, with no recent releases or commits, so maintenance and compatibility risk are substantial.

Latest 2.0.0-alpha1PackagistPackagist

35%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The package has 22 releases but none in the last 12 months, and its latest release was more than nine years ago. That long release gap is strong evidence of abandonment risk.

Repo commit activitydanger

There were zero commits and zero active maintainers in the last three months, reinforcing the release-history evidence that ongoing maintenance is absent.

Repo issue activitycaution

There were no new or merged pull requests and no issue activity in the last month. This is consistent with an inactive project, although open-issue data is unavailable.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and maintenance gap, not evidence of maliciousness.

Repository archivedcaution

The repository is not archived, but it was last pushed more than nine years ago, so its unarchived status does not offset the stale maintenance evidence.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Liip AG
Driebit
Community contributions

Direct Dependencies

DependencyLast ReleaseScore
symfony/http-foundation
Version ~2.8.13||^3.1.6
symfony/framework-bundle
Version ^2.8||^3.0
friendsofsymfony/http-cache
Version ^2.0.0-beta1

Weekly Downloads

Info

Last Published
9 years ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform