Package Health

3makkk/bedrock

There is no security policy or security-scanning tooling, which leaves maintenance practices difficult to verify. The package is documented and licensed, but that does not offset its lack of ongoing support.

Latest 1.8.9PackagistPackagist

15%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

63

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no replacement specified. Package-level deprecation is a severe warning against taking a new dependency.

Release historydanger

The latest release was about 8 years ago, with no releases in the last 12 months. Although the project has a long history and 57 releases, this release is far beyond a normal maintenance window.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last 3 months. Combined with the old last push, this indicates ongoing maintenance has effectively stopped.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. This is a maintenance and transparency gap for a package that manages a WordPress application stack.

Repository archivedcaution

The repository is not archived, which avoids the strongest abandonment signal. However, its last push was about 7 years ago, so the unarchived status provides little practical reassurance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Scott Walkinshaw
Ben Word

Direct Dependencies

DependencyLast ReleaseScore
oscarotero/env
Version ^1.1.0
vlucas/phpdotenv
Version ^2.0.1
composer/installers
Version ^1.4
johnpbloch/wordpress
Version 4.9.5
roots/wp-password-bcrypt
Version 1.0.0

Weekly Downloads

Info

Last Published
8 years ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform