Package Health

satooshi/symfony2contrib-common-bundle

Risky to adopt: this package has had only one release, with no release activity since January 2013, and its repository has not been updated since then. It is not deprecated or archived, but the minimal documentation and lack of repository security policy add transparency concerns.

Latest 0.1.0PackagistPackagist

32%

Total Score

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

58

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The package has only one release, and its latest release was about 13 years ago with no releases in the last 12 months, which is strong evidence of abandonment risk.

Package scaffoldingcaution

A README is present but only 78 characters long, while tests and a changelog are absent; the missing tests and changelog are normal for a published artifact, but the extremely limited consumer documentation is a transparency gap.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package, leaving uncertainty about whether the linked repository directly backs this release.

Repository archivedcaution

The repository is not marked archived, which avoids the strongest abandonment signal, but its last push was about 13 years ago and does not offset the stale release history.

Security policycaution

The repository has no security policy. This is a modest transparency gap, though the package is small and has no recent activity suggesting an active security process.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Kitamura Satoshi

Direct Dependencies

DependencyLast ReleaseScore
symfony/symfony
Version >=2.1
—
—

Weekly Downloads

Info

Last Published
13 years ago
Created
13 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform