Package Health

getpop/media

This release has strong evidence of sustained development: it has 162 releases over roughly 5 years, 33 releases in the last 12 months, a stable non-prerelease version, recent repository activity, tests, a license, and no install-time lifecycle scripts. However, Packagist marks the package as abandoned and identifies pop-schema/media as its replacement, which is a decisive dependency risk: developers should migrate to the replacement rather than adopt getpop/media. The repository is organization-owned and active, but recent work is concentrated entirely in one contributor, with no security scanning or security policy and negligible repository popularity.

Latest 19.2.4PackagistPackagist

22%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Registry deprecationdanger

Packagist marks the package as abandoned and names pop-schema/media as the replacement. This is a severe adoption risk even though the linked repository remains active, because new consumers should depend on the replacement package instead.

Repo bus factorcaution

All 15 commits in the last 3 months came from one contributor. Organizational ownership provides some ability to hand off maintenance, but the observed contributor concentration remains a resilience concern.

Repo popularitycaution

The repository has zero stars and forks and one watcher. This indicates limited community visibility, but popularity is supporting evidence rather than a decisive health criterion, especially given the demonstrated release and commit activity.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are configured. The build setup is appropriate, while the absent security automation is a modest hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
getpop/engine
Version ^19.2.4
—
—
pop-cms-schema/schema-commons
Version ^19.2.4
—
—

Weekly Downloads

Info

Last Published
19 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform