Package Health

spryker/configurable-bundle

This release appears healthy and suitable to depend on: it is a stable, non-deprecated release from a long-lived package with a matching organization-owned repository, documented source structure, tests, changelog, and recent activity from five contributors. The main reservations are repository security hygiene—no security policy, no detected security-scanning tools, and no top-level GitHub Actions token permissions—and the repository's very low public popularity, although the latter is less concerning for an organization-backed package with balanced recent contribution activity.

Latest 2.6.1PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo popularitycaution

The repository has zero stars and forks, with six watchers, so public adoption evidence is weak. This is only a supporting concern because the repository is organization-owned and other maintenance signals are positive.

Repo toolingcaution

Composer build tooling is present, supporting reproducible project handling, but no security-scanning tools were detected. The missing security tooling is a modest supply-chain hygiene gap.

Security policycaution

The repository has no security policy, reducing transparency about vulnerability reporting and response procedures. Other repository and maintenance evidence does not compensate for this documentation gap.

Token permissionscaution

The sole workflow lacks top-level token permissions. Although no write permissions were explicitly observed, the absence of an explicit restrictive declaration is a workflow-hardening gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
spryker/event
Version ^2.0.0
—
—
spryker/kernel
Version ^3.33.0
—
—
spryker/locale
Version ^3.2.3 || ^4.0.0
—
—
spryker/glossary
Version ^3.7.0
—
—
spryker/transfer
Version ^3.25.0
—
—

Weekly Downloads

Info

Last Published
20 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform