Package Health

frojd/frojd-bedrock

The package includes a clear README, matching source repository, MIT licensing, and a security policy. Two active contributors support the project, though its build and security tooling are limited.

Latest v2.2.1PackagistPackagist

67%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Dependency profilecaution

The package declares 13 runtime dependencies, including WordPress, plugins, deployment components, and monitoring. This is a relatively broad dependency surface for a boilerplate, but it is coherent with the package's full-stack role.

Release historycaution

The latest registry release was published in August 2018, with no releases in the last 12 months. Recent repository commits partly compensate, but the release itself is substantially stale.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, while seven issues remain open. This weakens evidence of responsive project management, although recent commits provide some compensation.

Repo toolingcaution

The repository reports no build tooling and no security scanning tools. For a deployment-oriented WordPress scaffold, the absence of security scanning is a genuine maintenance and transparency gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Mikael Engström

Direct Dependencies

DependencyLast ReleaseScore
sentry/sentry
Version *
—
—
vlucas/phpdotenv
Version ^2.0.1
—
—
composer/installers
Version ~1.0.12
—
—
johnpbloch/wordpress
Version *
—
—
wpackagist-plugin/nginx-cache
Version *
—
—

Weekly Downloads

Info

Last Published
8 years ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform