Package Health

getpop/custompostmeta-wp

This release shows strong ongoing maintenance and reasonable package hygiene: it has 162 releases over approximately 5 years, 33 releases in the last 12 months, a stable version, recent commits, an active unarchived organization-owned repository, a license, tests, and no install-time lifecycle scripts. However, Packagist marks the package as abandoned and points to pop-schema/custompostmeta-wp as its replacement; that is a decisive adoption risk because dependents may be relying on a package that the publisher no longer intends to support. The single-contributor activity and absent security policy add secondary concerns, so this package should not be newly adopted despite its otherwise healthy maintenance signals.

Latest 19.2.4PackagistPackagist

22%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Registry deprecationdanger

Packagist marks the package as abandoned and provides pop-schema/custompostmeta-wp as a replacement. This is a severe dependency-sustainability risk even though recent releases exist.

Repo bus factorcaution

All 16 recent commits came from one contributor, creating concentration risk. The organization-owned repository provides some ability to hand maintenance off, so this remains a secondary concern rather than a severe standalone risk.

Repo popularitycaution

The repository has 0 stars and 0 forks and only 1 watcher. This is weak supporting evidence for community adoption, but popularity alone is not decisive for a focused component.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tools were detected. The build tooling is appropriate, while the missing scanning coverage is a modest supply-chain hygiene gap.

Security policycaution

The linked repository has no security policy. This weakens vulnerability-reporting transparency, although it does not by itself establish that the package is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
pop-cms-schema/metaquery-wp
Version ^19.2.4
—
—
pop-cms-schema/custompostmeta
Version ^19.2.4
—
—
pop-cms-schema/customposts-wp
Version ^19.2.4
—
—

Weekly Downloads

Info

Last Published
18 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform