Package Health

getpop/user-roles

This release shows strong ongoing project activity and reasonable package hygiene: it has a long release history, frequent recent releases, a stable version, an explicit GPL license, tests in the artifact and repository, no install-time lifecycle scripts, and an active unarchived repository backed by an organization. However, the package is explicitly marked abandoned on Packagist and has a replacement package, which is a decisive adoption risk: developers should depend on pop-schema/user-roles instead. Maintenance is also concentrated entirely in one contributor, and the repository has no security scanning or security policy, adding secondary concerns despite recent activity.

Latest 19.2.4PackagistPackagist

20%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the package as abandoned and identifies pop-schema/user-roles as its replacement. This is a severe adoption and maintenance risk for a new dependency, even though the repository remains active.

Repo bus factorcaution

One contributor made all 15 commits in the last 3 months, giving the repository a 100% top-contributor share. Even with organization backing, no second active contributor is shown, so continuity depends heavily on one person.

Repo issue activitycaution

There were no new issues or pull requests in the last month, and no pull requests were merged. With recent commits this is not evidence of abandonment, but it offers limited evidence of broader community activity.

Repo popularitycaution

The repository has only 3 stars, 1 fork, and 1 watcher. Low popularity is supporting evidence rather than a verdict, but it provides little external resilience or adoption evidence.

Repo toolingcaution

Composer is used as a build tool, but no security-scanning tools are present. Build tooling is appropriate, while the absence of security scanning is a hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
pop-cms-schema/users
Version ^19.2.4
—
—

Weekly Downloads

Info

Last Published
19 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform