Package Health

brianhenryie/bh-wp-private-uploads

This release appears healthy and reasonably safe to depend on from a maintenance and supply-chain transparency perspective. It has been actively released, with 6 releases in the last 12 months and a latest release on 2026-09-08, while the linked repository is not archived and shows 126 commits from two active contributors in the last 3 months. The repository contains tests, changelog documentation, CI workflows, Composer tooling, and Dependabot scanning, and the package is clearly linked to its matching source repository. Remaining concerns are the 0.x version line, install-time Composer scripts, the absence of a security policy, and workflows that do not declare top-level token permissions; these warrant review but do not outweigh the strong recent maintenance and repository evidence.

Latest 0.5.1PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

63

Health Score Breakdown

Lifecycle scriptscaution

The package runs post-install-cmd and post-update-cmd scripts, creating additional install-time execution surface that should be reviewed before adoption.

Project backingcaution

The repository is owned by an individual user rather than an organization, so maintenance continuity depends primarily on the observed individual and contributor activity.

Repo popularitycaution

The repository has only 3 stars, 0 forks, and 1 watcher, so external adoption evidence is limited; this is a supporting concern rather than a health verdict for a small package.

Security policycaution

The repository has no SECURITY.md or other detected security policy, reducing transparency around vulnerability reporting and response.

Token permissionscaution

All 8 workflows lack top-level token permissions declarations, although none declares top-level write permissions and three constrain permissions at job level; explicit least-privilege declarations would improve CI hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

BrianHenryIE
Chris Dennis

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1 || ^2 || ^3
—
—
wptrt/admin-notices
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
20 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform