Package Health

whatwedo/search-bundle

The source project remains maintained enough to provide tests, documentation, and a matching organization-owned repository. Its MIT licensing and lack of install scripts reduce adoption friction, but the package should be replaced rather than newly adopted.

Latest v2.3.1PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

64

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned and names araise/search-bundle as its replacement. This is a substantial adoption risk even though the release itself is not individually withdrawn.

Release historydanger

The latest registry release was on August 19, 2022, with no releases in the last 12 months. That long release gap raises abandonment and compatibility risk.

Repo commit activitycaution

The repository had no commits and no active maintainers in the last 3 months, which conflicts with the repository's recent push metadata and provides little evidence of ongoing development.

Repo toolingcaution

The repository uses Make and Composer build tooling, but no security scanning tools were detected. The missing scanning is a modest transparency gap rather than a standalone adoption blocker.

Security policycaution

No security policy was found in the linked repository, leaving vulnerability-reporting expectations unclear. This is a transparency weakness, not evidence of malicious behavior.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ueli Banholzer
Felix Imobersteg
Nicolo Singer
Maurizio Monticelli

Direct Dependencies

DependencyLast ReleaseScore
symfony/http-kernel
Version ~4.0|~5.0
whatwedo/core-bundle
Version ^0.4
symfony/framework-bundle
Version ~4.0|~5.0

Weekly Downloads

Info

Last Published
4 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform