Package Health

totalcrm/microsoft-graph-bundle

The README, MIT license, and package-to-repository match provide useful transparency. Very low adoption and no security policy add little reassurance for a long-quiet integration bundle.

Latest 1.0.5PackagistPackagist

43%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The latest release was in May 2022, and there have been no releases in the last 12 months despite the package being over four years old. This is strong evidence of abandonment risk.

Repo commit activitydanger

There were zero commits and zero active maintainers in the last three months. Combined with the last release being over four years ago, this materially increases abandonment risk.

Project backingcaution

The repository is owned by a user account rather than an organization, so the single registry maintainer does not have organizational backing to compensate for inactivity.

Repo popularitycaution

The repository has only 2 stars, 1 fork, and 1 watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of a broad support base.

Repo toolingcaution

Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools are configured. The missing scanning is a hygiene gap rather than proof of unsafe code.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Romanenko Aleksandr

Direct Dependencies

DependencyLast ReleaseScore
symfony/asset
Version ^4.4 || ^5.3 || ^6.0
symfony/cache
Version ^4.4 || ^5.3 || ^6.0
symfony/config
Version ^4.4 || ^5.3 || ^6.0
symfony/console
Version ^4.4 || ^5.3 || ^6.0
symfony/routing
Version ^4.4 || ^5.3 || ^6.0

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform