Package Health

getpop/post-tags

This release has strong evidence of ongoing development and reasonable package hygiene: it has 161 releases over roughly 5 years, 33 releases in the last 12 months, a stable non-prerelease version, a linked non-archived organizational repository, recent commits, a license file, tests, and no install-time lifecycle scripts. However, the package is explicitly marked abandoned on Packagist with a replacement package, which is a major dependency risk even though the repository remains active; maintenance is concentrated entirely in one contributor, and the repository has no security scanning or security policy. Prefer the replacement package unless compatibility requirements require this package and you have verified its migration path.

Latest 19.2.4PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Registry deprecationdanger

Packagist marks the package as abandoned and names pop-schema/post-tags/ as its replacement. This is a major adoption and continuity risk despite the absence of repository archival.

Repo bus factorcaution

All 15 recent commits came from one contributor, producing a complete single-contributor concentration. Organizational ownership provides some maintenance context, but there is still a meaningful continuity risk.

Repo popularitycaution

The repository has only 1 star and no forks, indicating limited public adoption. Popularity is supporting evidence rather than decisive, so this is a caution rather than a severe finding.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are detected. The build setup is appropriate for the package, while the missing security automation lowers transparency somewhat.

Security policycaution

The repository has no security policy. The README provides an email-based security reporting path, which partially compensates for the missing SECURITY.md but leaves formal disclosure guidance limited.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
pop-cms-schema/tags
Version ^19.2.4
pop-cms-schema/posts
Version ^19.2.4

Weekly Downloads

Info

Last Published
16 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform