Package Health

setono/tag-bag-bundle

Usable with caveats: this is a mature, licensed Symfony bundle with a recent release, repository tests, and organization backing. Commit activity has been absent for three months, and the repository lacks a security policy and explicit workflow token permissions.

Latest v3.3.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The package has been maintained since 2019 with 31 releases and a release about five months ago, but only one release appeared in the last 12 months, indicating a slower cadence.

Repo commit activitycaution

There were zero commits and zero active maintainers in the last three months. The recent release partly offsets this because release activity is present, but the lack of current development activity remains a maintenance risk.

Repo issue activitycaution

The repository has five open issues, with one new issue and no issues or pull requests closed in the last month; this is a modest maintenance concern but not evidence of abandonment by itself.

Repo toolingcaution

Composer build tooling is present, but no security scanning tool was detected, leaving a security-process gap in the repository.

Security policycaution

The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Joachim Løvgaard

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.0
setono/tag-bag
Version ^2.5
symfony/config
Version ^6.4 || ^7.4
webmozart/assert
Version ^1.11
symfony/http-kernel
Version ^6.4 || ^7.4

Weekly Downloads

Info

Last Published
5 months ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform