wikimedia/toolforge-bundle 1.8.0 appears broadly dependable: it has been published since 2018, has 51 releases, includes a license, tests, a substantial README, and a complete-looking package tree, and is backed by a non-archived Wikimedia organization repository. The main concerns are that only one release occurred in the last 12 months, there were no active maintainers or commits in the last 3 months, repository security scanning and a security policy are absent, and the CI workflow does not declare top-level token permissions. These are meaningful maintenance and transparency gaps, but they do not outweigh the package's long release history, current publication, testing, and organizational backing.
76%
Total Score
88
83
80
The package has a long history of 51 releases since 2018, but only 1 release in the last 12 months despite a historical median interval of about 13 days, indicating materially slower recent release activity.
No commits and no active maintainers were recorded in the last 3 months, despite the repository being recently pushed and the package receiving a release, indicating a recent maintenance lull.
The repository has modest adoption indicators with 15 stars, 5 forks, and 10 watchers; this is limited supporting evidence but not by itself a dependency-health failure.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-process gap.
The repository has no SECURITY policy, reducing transparency about vulnerability reporting and coordinated response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/cache Version ^4.4|^5.0|^7|^8 | — | — |
symfony/config Version ^4.4|^5.0|^7.0|^8 | — | — |
symfony/console Version ^4.4|^5.2|^7|^8 | — | — |
symfony/process Version ^4.4|^5.0|^7.0|^8 | — | — |
symfony/routing Version ^4.4|^5.0|^7.0|^8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.