Package Health

apermo/phpstan-wordpress-rules

The package is clearly documented, licensed, tested in its repository, and released with notes. Maintenance depends on one contributor, while workflow template-injection findings and unpinned actions leave avoidable supply-chain hygiene concerns.

Latest v0.3.1PackagistPackagist

67%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Project backingcaution

The registry namespace and repository are owned by the same user account, which supports package identity but does not provide the maintenance redundancy of organization ownership.

Repo bus factorcaution

One contributor made all commits in the last three months, concentrating maintenance responsibility entirely in a single person. The repository owner is a user account, so no organization backing is shown to offset that concentration.

Repo commit activitycaution

Only two commits were made in the last three months, showing limited recent activity even though a release was published during that period.

Repo toolingcaution

Composer is used for the build, but no repository security-scanning tool was detected. This is a modest transparency and assurance gap rather than evidence of unsafe code.

Security policycaution

The repository has no security policy, leaving no documented path for reporting vulnerabilities or explaining security response expectations.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Christoph Daum

Direct Dependencies

DependencyLast ReleaseScore
phpstan/phpstan
Version ^2.0
phpstan/phpstan-strict-rules
Version ^2.0
swissspidy/phpstan-no-private
Version ^1.0
szepeviktor/phpstan-wordpress
Version ^2.0
phpstan/phpstan-deprecation-rules
Version ^2.0

Weekly Downloads

Info

Last Published
1 month ago
Created
6 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform