Package Health

graphql-by-pop/graphql-endpoint-for-wp

This is a healthy, actively maintained release with a five-year history, 162 releases, 33 releases in the last 12 months, a stable non-prerelease version, and a recent push to an unarchived organization-owned repository. Licensing, repository/package identity, tests, build scaffolding, and dependency scope are clear, and there are no install-time lifecycle scripts or dangerous workflow findings. The main concerns are that all 14 commits in the last three months came from one contributor, the repository has very little measured popularity, no security scanning or security policy was found, and no changelog was present in the artifact or repository; these reduce resilience and transparency but do not outweigh the strong release and maintenance evidence.

Latest 19.2.4PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Package scaffoldingcaution

The artifact has a substantial README and tests, and the source repository also reports tests; the missing changelog is a modest transparency gap, although the README directs users to a changelog that is not present in the collected repository evidence.

Repo bus factorcaution

One contributor made all 14 commits in the last three months, creating a meaningful bus-factor and continuity concern; organization ownership provides some potential maintenance backing but does not remove the concentration risk.

Repo issue activitycaution

There are no recent issues or pull requests recorded, and the open issue count is unknown; this is neutral-to-weak evidence because low issue volume can also reflect a small project.

Repo popularitycaution

The repository has only 2 stars, 1 fork, and 1 watcher, indicating limited adoption evidence; popularity is supporting evidence rather than a decisive health criterion.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving a security-hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
pop-api/api-graphql
Version ^19.2.4
—
—
pop-api/api-endpoints-for-wp
Version ^19.2.4
—
—

Weekly Downloads

Info

Last Published
19 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform