Package Health

teamneusta/pimcore-http-cache-bundle

The repository is actively maintained by three contributors and the package includes documentation, tests in source, and release notes. All six workflow actions are unpinned, and no security policy is provided.

Latest v0.7.1PackagistPackagist

79%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

Only two releases have been published over 228 days, with a median interval of about 83 days. This is limited release history, though repository activity provides compensating evidence of ongoing work.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected; this is a modest transparency and hygiene gap rather than evidence of abandonment.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.

Version stabilitycaution

Version v0.7.1 is not a stable major release, so the API may still change; it is not a prerelease, which partly reduces that concern.

Workflow auditcaution

Both workflows use read-only permissions, have no untrusted checkout or script-injection findings, and the audit completed fully. However, all six action references are unpinned, creating a supply-chain hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

team neusta GmbH

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^2.0 || ^3.0
—
—
symfony/config
Version ^6.4 || ^7.4
—
—
pimcore/pimcore
Version ^11.5 || ^12.0
—
—
symfony/contracts
Version ^2.5 || ^3.5
—
—
symfony/messenger
Version ^6.4 || ^7.4
—
—

Weekly Downloads

Info

Last Published
5 months ago
Created
8 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform