Package Health

tourze/easy-admin-menu-bundle

It has a clear MIT license, README, tests, and release notes, with a matching repository and no install scripts. Limited security tooling and a very small community add maintenance uncertainty.

Latest 1.0.1PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo commit activitycaution

The repository had zero commits and zero active maintainers in the last three months. Its non-archived state and recent release history provide some context, but do not offset the current maintenance pause.

Repo popularitycaution

The repository has zero stars and forks and only one watcher. Popularity is not required for a healthy small package, but this provides little external evidence of adoption or review.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. That leaves a modest transparency and maintenance gap.

Security policycaution

The repository has no security policy, so there is no documented route for reporting or handling vulnerabilities.

Workflow auditcaution

The audit analyzed both workflows completely and found no dangerous triggers, untrusted checkouts, script injection, or write-wide permissions. However, all four action references are unpinned, weakening build reproducibility and supply-chain control.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
symfony/yaml
Version ^7.3
—
—
symfony/config
Version ^7.3
—
—
knplabs/knp-menu
Version ^3.7
—
—
symfony/http-kernel
Version ^7.3
—
—
symfony/twig-bundle
Version ^7.3
—
—

Weekly Downloads

Info

Last Published
10 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform