Package Health

tourze/condition-system-bundle

A large runtime dependency set and no security policy add upkeep and transparency concerns. The package includes tests, a README, a matching MIT license, and a GitHub release, but recent repository activity is absent.

Latest 0.1.1PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Dependency profilecaution

The package declares 23 runtime dependencies, including framework, ORM, administration, and several project-specific bundles, creating a relatively broad maintenance and compatibility surface. The dependency set fits the bundle's stated functionality but still increases upkeep risk.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months, which raises maintenance and abandonment concerns for a young package. The recent release history provides some compensating evidence, but does not show ongoing development.

Security policycaution

The repository has no security policy, reducing transparency about vulnerability reporting and maintenance response. This is a meaningful gap for a Symfony bundle with 23 runtime dependencies.

Version stabilitycaution

Version 0.1.1 is not a prerelease, but the 0 major version indicates an early-stage API with potentially limited maturity. The package's tests, README, and release notes provide some compensating evidence.

Workflow auditcaution

All 4 analyzed action references are unpinned, weakening build reproducibility and increasing exposure to changed upstream actions. The audit found no injection sinks, dangerous triggers, or high-severity findings, which keeps this as a hygiene concern rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3|^2|^1
doctrine/orm
Version ^3.0
symfony/yaml
Version ^7.3
doctrine/dbal
Version ^4.0
symfony/config
Version ^7.3

Weekly Downloads

Info

Last Published
10 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform