Package Health

tourze/json-rpc-container-bundle

Maintenance is currently quiet, with no active maintainers or commits in the last three months, and all four workflow actions are unpinned. Tests, release notes, licensing, and a matching repository provide useful evidence of basic project discipline.

Latest 2.0.0PackagistPackagist

64%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last three months, which raises a genuine maintenance and abandonment concern. A release was still published within the observed history, partly offsetting the inactivity.

Repo popularitycaution

The repository has 0 stars and 0 forks, with 1 watcher, so there is little visible community adoption or external review. Popularity is supporting evidence only and does not outweigh the package's concrete maintenance signals.

Security policycaution

The repository has no security policy, reducing transparency about vulnerability reporting and response. This is a hygiene gap rather than evidence that the package is unsafe.

Workflow auditcaution

All 4 analyzed action references are unpinned, leaving workflow dependencies exposed to unexpected upstream changes. The audit found no dangerous triggers, untrusted checkouts, script injection, or other reported findings.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3|^2|^1
—
—
symfony/yaml
Version ^7.3
—
—
psr/container
Version ^1.1|^2.0
—
—
symfony/config
Version ^7.3
—
—
monolog/monolog
Version ^3.1
—
—

Weekly Downloads

Info

Last Published
9 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform