Package Health

rikudou/unleash-sdk-bundle

The source includes tests, a clear license, and a recent release, but no commits in the last three months. Its workflows use unpinned actions and inherit secrets, adding avoidable maintenance risk.

Latest v0.12.285PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned and names unleash/symfony-client-bundle as its replacement. This is a direct maintenance concern for anyone starting a new dependency.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. That inactivity is concerning despite the recent release history.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package. Although subpackages can use monorepos, both gaps make package ownership less transparent.

Security policycaution

No security policy was found in the repository. This is a modest transparency gap, though the reported security scanning provides partial compensation.

Workflow auditcaution

All 17 analyzed action references are unpinned, and the audit found a high-confidence medium-severity secrets-inherit issue in a pull_request_target workflow. No untrusted checkout or script injection was found, which limits the impact.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
nyholm/psr7
Version ^1.0
—
—
symfony/cache
Version ^5.0 | ^6.0 | ^7.0 | ^8.0
—
—
unleash/client
Version ^2.4
—
—
symfony/http-client
Version ^5.0 | ^6.0 | ^7.0 | ^8.0
—
—
symfony/event-dispatcher
Version ^5.0 | ^6.0 | ^7.0 | ^8.0
—
—

Weekly Downloads

Info

Last Published
8 months ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform