Package Health

sonata-project/news-bundle

Unfit to use for new projects: the package is marked abandoned and its source repository is archived, with no releases or commits for roughly five years. It has solid historical packaging, tests, and licensing, but those do not offset the lack of ongoing maintenance.

Latest 3.17.0PackagistPackagist

15%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

63

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning against taking a new dependency despite the package's otherwise established history.

Release historydanger

The package has 32 releases and a long history, but it has had no release in roughly five years and none in the last 12 months. The historical cadence does not compensate for the prolonged release gap.

Repo commit activitydanger

The repository recorded no commits and no active maintainers in the last three months, consistent with abandonment rather than active maintenance.

Repository archiveddanger

The linked source repository is archived and was last pushed in December 2021, so it is no longer maintained through that repository.

Security policycaution

The repository has no security policy. This is a transparency gap, although the stronger abandonment signals are the primary reason this release is unfit.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Thomas Rabaix
Sonata Community

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^2.12.1
symfony/form
Version ^4.4
symfony/mime
Version ^4.4.10 || ^5.1
symfony/config
Version ^4.4
symfony/mailer
Version ^4.4 || ^5.1

Weekly Downloads

Info

Last Published
5 years ago
Created
13 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform