Package Health

sensio/distribution-bundle

Unfit to use for new projects: the package is abandoned on Packagist, its repository is archived, and it has had no release since June 2019. The MIT license and clear README do not offset the lack of ongoing maintenance.

Latest v5.0.25PackagistPackagist

18%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

50

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption risk because the registry itself indicates the package is no longer maintained.

Release historydanger

The package has 138 historical releases, but none in the last 12 months and the latest release was in June 2019. Its long release gap strongly indicates abandonment despite its formerly active history.

Repo commit activitydanger

There were zero commits and zero active maintainers during the last three months. This confirms that the project is not receiving current maintenance.

Repository archiveddanger

The linked source repository is archived, with its last push in January 2020. An archived repository indicates active maintenance has ended.

Repo package mentioncaution

The linked repository name does not match the package name and its README does not mention the package, creating some uncertainty about the repository linkage. The organization backing provides context, but does not remove this transparency concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Fabien Potencier

Direct Dependencies

DependencyLast ReleaseScore
symfony/config
Version ~2.3|~3.0
symfony/process
Version ~2.3|~3.0
symfony/filesystem
Version ~2.3|~3.0
symfony/http-kernel
Version ~2.3|~3.0
symfony/class-loader
Version ~2.3|~3.0

Weekly Downloads

Info

Last Published
7 years ago
Created
14 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform