Package Health

26b/wp-attachments

A README, release notes, organization backing, and security scanning provide useful transparency. The repository has no commits or active maintainers in the last three months, while all eight workflow actions are unpinned and the license declarations disagree.

Latest 0.0.4PackagistPackagist

57%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

63

Health Score Breakdown

Licensecaution

The artifact contains a license file and the repository also has one, but the manifest declares GPL-3.0 while the detected license is AGPL-3.0. The mismatch creates real licensing uncertainty.

Lifecycle scriptscaution

post-install-cmd and post-update-cmd scripts run during Composer installation or updates, adding execution-time supply-chain exposure beyond ordinary dependency resolution.

Release historycaution

Four releases over 419 days, including two in the last 12 months and a median interval of about 74 days, show some release continuity but not a mature cadence.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance warning, although the recent repository push and releases provide limited counterevidence.

Repo issue activitycaution

There are nine open pull requests, with no new or merged pull requests in the last month. The backlog and lack of recent integration suggest slowed project activity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

26b

Direct Dependencies

DependencyLast ReleaseScore
26b/wp-framework
Version ^1.6
—
—

Weekly Downloads

Info

Last Published
8 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform