Package Health

whatwedo/core-bundle

The repository is organization-backed and recently updated, with tests, a changelog, and security scanning. Maintenance is concentrated in one contributor, and the package remains pre-1.0.

Latest v0.5.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package abandoned and identifies araise/core-bundle as the replacement. This is a direct warning against starting a new dependency on this package.

Release historycaution

The package has 11 releases since January 2017, but its latest registry release was in March 2023 and there were no releases in the last 12 months. That weakens confidence in ongoing release maintenance.

Repo bus factorcaution

All five recent commits came from one contributor, leaving maintenance capacity concentrated in a single person. Organization backing provides some handoff potential but does not eliminate this weakness.

Security policycaution

The repository has no published security policy. That is a transparency gap for reporting and handling vulnerabilities.

Version stabilitycaution

Version v0.5.0 is not a stable major release, so its API may still change. This adds compatibility risk alongside the package's abandoned status.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ueli Banholzer
Felix Imobersteg
Nicolo Singer

Direct Dependencies

DependencyLast ReleaseScore
symfony/intl
Version ~4.0|~5.0
symfony/console
Version ~4.0|~5.0
symfony/http-kernel
Version ~4.0|~5.0
doctrine/collections
Version ~1.0
symfony/framework-bundle
Version ~4.0|~5.0

Weekly Downloads

Info

Last Published
3 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform