Package Health

thinkawitch/tag-bundle

The package is clearly licensed, has a matching repository, and avoids install-time scripts. Its small user-owned project has no tests or security policy, while maintenance stopped after the initial release, leaving longer-term support uncertain.

Latest v0.9.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

This package has only one release, v0.9.0, published 488 days ago, with no releases in the last 12 months. That is meaningful evidence of limited maintenance for a pre-1.0 library.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the lack of follow-up releases. This raises support and abandonment risk, though the repository is not archived.

Repo popularitycaution

The repository has 0 stars, 0 forks, and 1 watcher, providing little evidence of external adoption or a broader support community. Popularity is only supporting evidence, so this remains a moderate concern rather than a verdict.

Security policycaution

The linked repository has no security policy. For a Symfony bundle, this is a transparency gap, although it does not by itself indicate unsafe code.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Andrew Sinkevitch

Direct Dependencies

DependencyLast ReleaseScore
doctrine/orm
Version ^2.17
symfony/ux-autocomplete
Version ^2.14
doctrine/doctrine-bundle
Version ^2.11

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform