Package Health

zenstruck/signed-url-bundle

There has been no new release or commit activity since December 2021, leaving the sole version several years old. The package includes a substantial README, repository tests, a license, and a security policy, but those strengths do not offset its lack of ongoing maintenance.

Latest v0.1.0PackagistPackagist

8%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

50

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned and names zenstruck/uri as its replacement. This is a direct indication that new projects should not adopt this package.

Release historydanger

This is the package's only release, published on December 22, 2021, with no releases in the last 12 months. The release history shows the project was never maintained beyond its initial publication.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the archived state and indicating no current maintenance capacity.

Repository archiveddanger

The linked repository is archived and was last pushed on December 22, 2021. Archived source removes the normal path for fixes and maintenance.

Workflow auditcaution

The single workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings. However, all four action references are unpinned, which is a minor supply-chain hygiene weakness.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Kevin Bond

Direct Dependencies

DependencyLast ReleaseScore
symfony/polyfill-php80
Version ^1.15
—
—
symfony/framework-bundle
Version ^4.4|^5.0|^6.0
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform