Package Health

getpop/pages

This release shows strong ongoing engineering activity and reasonable package hygiene: it has 162 releases over roughly 5 years, 33 releases in the last 12 months, a stable version line, an unarchived organization-owned repository, tests in the repository, and no install-time lifecycle scripts. However, Packagist explicitly marks version 19.2.4 as abandoned and points users to pop-schema/pages, which is a decisive adoption risk even though the repository was recently updated. The single-contributor activity and absence of a security policy add further caution. Developers should prefer the replacement package and migrate rather than take a new dependency on this abandoned package.

Latest 19.2.4PackagistPackagist

22%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Registry deprecationdanger

Packagist marks the package as abandoned and names pop-schema/pages as its replacement. This is a severe adoption and maintenance risk that outweighs the otherwise healthy release activity.

Maintainerscaution

Only one registry account has publish access. That is a limited publishing base, but the organization-owned repository and active release history partly compensate for the registry-side concentration.

Repo bus factorcaution

All 16 recent commits came from one contributor, giving a 100% top-contributor share and creating a real continuity risk. Organizational ownership provides some handoff potential but no second active contributor is evidenced.

Repo popularitycaution

The repository has 1 star, 0 forks, and 1 watcher, indicating a very small public user and contributor footprint. Popularity is only supporting evidence, but these counts provide little external resilience.

Repo toolingcaution

Composer is used as a build tool, but no security-scanning tools are reported. The missing scanning tooling is a hygiene gap, although it is not by itself evidence that the package is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
pop-cms-schema/customposts
Version ^19.2.4
—
—

Weekly Downloads

Info

Last Published
18 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform