Package Health

sulu/automation-bundle

This is a generally usable and established package: it has been released for about 9 years, has 23 releases including 7 in the last 12 months, is on a stable major version, is not deprecated, has an MIT license, and is backed by a non-archived organization repository with tests and active issue/PR maintenance. The main concerns are that the repository shows no commits or active maintainers in the last 3 months despite the current release, the repository does not explicitly match or mention the package name, and its workflows lack explicit token permissions and security scanning. These reduce transparency and maintenance confidence, but do not outweigh the package's release history, repository tests, project backing, and recent release activity.

Latest 3.0.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Dependency profilecaution

The package has 13 runtime dependencies, including core Sulu, Symfony, Doctrine, and task libraries; this is a meaningful dependency surface but is coherent with a framework bundle's functionality.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers over the last 3 months. The current release and recent issue/PR activity provide some compensation, but the lack of recent commit activity is a real maintenance concern.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package, creating uncertainty about the linkage between the registry package and the inspected source repository.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving a security-process gap.

Security policycaution

The repository has no security policy, which weakens vulnerability-reporting transparency and response expectations.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Sulu Community

Direct Dependencies

DependencyLast ReleaseScore
sulu/sulu
Version ^3.0
—
—
symfony/uid
Version ^6.4 || ^7.1 || ^8.0
—
—
doctrine/orm
Version ^2.17.3 || ^3.3
—
—
symfony/config
Version ^6.4 || ^7.1 || ^8.0
—
—
php-task/php-task
Version ^3.1
—
—

Weekly Downloads

Info

Last Published
28 days ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform