Package Health

survos/jsonl-bundle

Frequent releases, repository tests, and a substantial README support ongoing maintenance. Organization ownership and security scanning help, though the project remains dependent on one active contributor.

Latest 2.34.9PackagistPackagist

76%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Dependency profilecaution

The package declares 11 runtime dependencies, including several Symfony components and required PHP extensions; this is a meaningful integration surface for a small bundle, though the dependencies fit its documented feature set.

Repo bus factorcaution

One contributor made all 3 commits in the last 3 months, concentrating current maintenance in a single person; organization ownership partly reduces handoff risk but does not remove it.

Repo commit activitycaution

Only 3 commits were recorded in the last 3 months, which is modest relative to the very frequent release history and leaves maintenance activity looking thin.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for consumers.

Workflow auditcaution

Both workflows were analyzed without dangerous triggers or audit findings, but all 4 action references are unpinned, weakening build reproducibility and action supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0
—
—
symfony/lock
Version ^8.1
—
—
symfony/console
Version ^8.1
—
—
survos/kit-bundle
Version ^2.0
—
—
symfony/http-client
Version ^8.1
—
—

Weekly Downloads

Info

Last Published
2 days ago
Created
11 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform