Package Health

getpop/content-wp

This release shows strong ongoing maintenance evidence: it has existed for over five years, has 162 releases including 33 in the last 12 months, was released very recently, is not prerelease, and its linked repository received 14 commits in the last three months. It is licensed, includes a README and tests, uses Composer without install-time lifecycle scripts, and is backed by an organization-owned repository. However, the package is explicitly marked abandoned on Packagist with a replacement package, which is a major adoption risk even though development remains active, and the linked repository neither matches the package name nor mentions it in its README, creating uncertainty about package-to-source alignment. Commit activity is also concentrated entirely in one contributor, while the repository has no security policy or security scanning. Dependents should prefer the stated replacement unless compatibility requirements justify accepting the transition risk.

Latest 19.2.4PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Registry deprecationdanger

Packagist marks the package as abandoned and names getpop/custom-posts-wp as its replacement. This is a major dependency-safety and continuity concern despite the package still receiving recent releases.

Repo bus factorcaution

All 14 recent commits came from one contributor, creating concentration risk. Organization backing provides some mitigation, but no second active contributor is shown.

Repo issue activitycaution

There were no new issues or pull requests in the last month, and no pull requests were merged; this provides little evidence of community interaction, though the separate commit signal confirms ongoing maintainer activity.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package, leaving uncertainty about whether the linked repository directly corresponds to this release. A monorepo relationship may explain the mismatch, but the provided evidence does not establish that.

Repo popularitycaution

The repository has 2 stars, 0 forks, and 1 watcher, indicating limited adoption evidence. Popularity is supporting evidence rather than a verdict, so this is not treated as a major health defect.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
pop-cms-schema/customposts
Version ^19.2.4
—
—
pop-cms-schema/queriedobject-wp
Version ^19.2.4
—
—

Weekly Downloads

Info

Last Published
21 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform