Package Health

tanoconsulting/ezmigrationbundle2

The package has clear licensing, a substantial README, and release notes for this version. Its organization-owned repository is correctly matched, but maintenance and workflow hardening have both stopped short of current expectations.

Latest 1.0.5PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

90

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package has had no release in about 3 years and 3 months, with no releases in the last 12 months. Its 10-release history and existing stable version provide some maturity, but the long pause raises abandonment concern.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the last push in June 2023. This is a meaningful maintenance concern for a package used in application migrations.

Security policycaution

The linked repository has no security policy and no reported security-scanning tools. That weakens vulnerability-reporting and maintenance transparency, although it does not by itself indicate an unsafe release.

Workflow auditcaution

The only workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both action references are unpinned, leaving the build exposed to moving action versions.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Gaetano Giunta
Peter Halasz

Direct Dependencies

DependencyLast ReleaseScore
doctrine/dbal
Version ^2.11|^3.0
—
—
symfony/process
Version *
—
—
nikic/php-parser
Version ^4.2.2
—
—
symfony/validator
Version *
—
—
symfony/var-dumper
Version *
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform