Package Health

screamz/securedownload-bundle

Tests, a useful README, and an MIT license improve transparency. One maintainer and minimal repository adoption leave little support if compatibility problems arise.

Latest V1.1.0PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

60

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The latest release was published in October 2017, with no releases in the last 12 months. That nearly nine-year gap is strong evidence of abandonment risk for a dependency.

Repo commit activitydanger

The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap and indicating no current maintenance capacity.

Maintainerscaution

Only one registry account can publish the package. With no evidence of organization backing and no recent activity, this leaves a thin support base if issues arise.

Repo package mentioncaution

The repository name does not match the package name, and its README does not mention the package. Although the file tree appears consistent, this weakens confidence that the linked repository is the package's maintained home.

Repo popularitycaution

The repository has one star and no forks, providing little evidence of broad community review or backup support. Popularity is supporting evidence rather than a verdict, so this is a modest concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Andréas Hanss

Direct Dependencies

DependencyLast ReleaseScore
symfony/config
Version >=2.3,<4.0
—
—
symfony/http-kernel
Version >=2.1,<4.0
—
—
tedivm/stash-bundle
Version ~0.4
—
—
symfony/dependency-injection
Version >=2.1,<4.0
—
—

Weekly Downloads

Info

Last Published
8 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform