Package Health

automattic/liveblog

Liveblogging done right. Using WordPress.

Latest 1.13.0PackagistPackagist

45%

Total Score

unhealthy

The package strongly resembles another owner’s established package, creating a serious identity risk despite active maintenance.

Health Score Breakdown

Name lookalikedanger

The package is flagged as borrowing the identity of automattic/vipwpcs, a much more downloaded package owned by another publisher. Although artifact overlap is 0.0 and the README does not identify it as that package, the identity signal is a severe adoption risk.

Security policycaution

The repository has no published security policy, leaving reporting and response expectations less transparent despite release notes documenting a recent security fix.

Workflow auditcaution

All 7 workflows were analyzed, use read-only permissions, and pin all 22 action references. One high-confidence low-severity finding installs a package outside a lockfile, which is a limited hygiene concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Automattic

Direct Dependencies

DependencyLast ReleaseScore
composer/installers
Version ^1.0 || ^2.0
—
—

Weekly Downloads

Info

Last Published
4 days ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform