Package Health

prooph/event-store-symfony-bundle

The bundle is licensed, tested, documented, and backed by an organization-owned project. Unpinned workflow actions and the missing security policy add smaller maintenance concerns.

Latest v0.11.2PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package has 17 releases over roughly 10 years but none in the last 12 months; its latest release was on May 28, 2024, indicating a meaningful maintenance slowdown.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, which supports the broader evidence of stalled maintenance.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations undocumented; this is a transparency gap but not evidence that the package is unsafe.

Version stabilitycaution

Version 0.11.2 is not on a stable major version, although it is not marked as a prerelease and recent prerelease usage is zero.

Workflow auditcaution

All 6 of 6 analyzed action references are unpinned, reducing build reproducibility. The audit found no untrusted checkouts, script injection, elevated top-level writes, or other reported findings.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Alexander Miertsch
Sascha-Oliver Prolic
Malte Blättermann
Ralf Junghanns
Oskar Pfeifer-Bley

Direct Dependencies

DependencyLast ReleaseScore
symfony/config
Version ^5.4 || ^6.4 || ^7.0
symfony/messenger
Version ^5.4 || ^6.4 || ^7.0
prooph/event-store
Version ^7.9.0
symfony/http-kernel
Version ^5.4.39 || ^6.4 || ^7.0
symfony/framework-bundle
Version ^5.4 || ^6.4 || ^7.0

Weekly Downloads

Info

Last Published
2 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform