Package Health

setono/meta-conversions-api-bundle

Work with the Meta / Facebook Conversions API in your Symfony application

Latest v1.0.0-beta.1PackagistPackagist

62%

Total Score

caution

Usable with caveats: a high-confidence workflow template-injection finding is the main adoption risk.

Health Score Breakdown

Workflow auditdanger

Both workflows were analyzed without incomplete files, but all 21 action references are unpinned. More importantly, a high-confidence, high-severity template-injection finding may expand attacker-controlled input into code; the absence of dangerous trigger and untrusted-checkout counts does not compensate for that finding.

Dependency profilecaution

Fourteen runtime dependencies, including Symfony components and the related SDK, create meaningful compatibility surface for a beta bundle. The dependencies are coherent with the package's Symfony integration role rather than appearing excessive or unrelated.

Maintainerscaution

Only one registry account has publish access, which is a publishing continuity concern. However, the repository is organization-owned and recent repository activity shows active project backing.

Repo bus factorcaution

One contributor made all 27 commits in the last three months, creating a concentrated maintenance dependency. Organization ownership provides some handoff capacity, but no second active contributor is evidenced here.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap, not evidence of abandonment or unsafe code by itself.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Joachim Løvgaard

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.1 || ^2.0 || ^3.0
—
—
symfony/config
Version ^6.4 || ^7.4
—
—
composer/semver
Version ^3.0
—
—
symfony/messenger
Version ^6.4 || ^7.4
—
—
symfony/http-kernel
Version ^6.4 || ^7.4
—
—

Weekly Downloads

Info

Last Published
18 days ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform