Package Health

graphql-by-pop/graphql-request

This is a mature, actively released package with 162 releases over roughly 5 years, 33 releases in the last 12 months, a stable non-prerelease version, current repository activity, tests, a clear README, an explicit GPL-2.0-or-later license, and no install-time lifecycle scripts. The main concerns are that all 14 commits in the last 3 months came from one contributor, the repository has very low popularity, no security scanning or security policy was detected, and no changelog is present; these reduce resilience and transparency but do not outweigh the strong release and maintenance evidence. Overall, it appears reasonable to depend on, with normal single-maintainer and security-process caveats.

Latest 19.2.4PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Maintainerscaution

Only one registry publishing maintainer is listed, which is a potential publishing continuity concern. However, the repository is organization-owned and shows sustained recent releases, so this is not treated as a severe risk.

Repo bus factorcaution

One contributor made all 14 commits in the last 3 months, creating a genuine continuity and bus-factor concern. Organization ownership provides some structural backing but does not show that another contributor is currently active.

Repo popularitycaution

The repository has only 2 stars, 1 fork, and 1 watcher. This indicates limited external adoption or visibility, but popularity is supporting evidence rather than a health verdict.

Repo toolingcaution

Composer build tooling is present, but no security scanning tool was detected. The missing scanning evidence is a security-process hygiene gap rather than evidence of maliciousness.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
pop-api/api-graphql
Version ^19.2.4

Weekly Downloads

Info

Last Published
14 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform