Package Health

xavierleune/ting_bundle

It has Apache-2.0 licensing, tests, a changelog, release notes, and no install-time scripts. The absent security policy and limited observable history leave some transparency and continuity uncertainty.

Latest 3.12.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

There are 38 releases, all within the last 12 months, but the recorded package age is 0 days and the releases are clustered on the collection date. This shows active publishing but gives little evidence of long-term cadence.

Repo toolingcaution

Composer is used for builds, but no security scanning tool was detected. The missing scanner is a modest maintenance-hygiene gap, not evidence of unsafe code.

Security policycaution

The repository has no security policy. This reduces transparency about vulnerability reporting and response expectations, although it does not by itself show poor maintenance.

Workflow auditcaution

The single workflow was fully analyzed with no untrusted checkout, injection, or high-confidence audit findings, but all 3 action references are unpinned. That leaves avoidable build-integrity risk, while the lack of a top-level permissions block is acceptable on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
doctrine/cache
Version ^1.10
—
—
symfony/config
Version ^7.0
—
—
ccmbenchmark/ting
Version ^3.13
—
—
symfony/stopwatch
Version ^7.0
—
—
symfony/validator
Version ^7.0
—
—

Weekly Downloads

Info

Last Published
3 days ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform