Package Health

helsingborg-stad/wp-page-for-post-type

This is a mature, actively released MIT-licensed package with 21 releases since 2017, seven releases in the last 12 months, a stable version line, current repository activity at release time, repository tests, build tooling, and security scanning. The main concerns are that repository commits show no activity in the last three months, the linked repository does not match the package name or mention it in its README, and the release workflow lacks top-level token permissions; these reduce transparency and maintenance confidence but are not sufficient to make the package unfit to depend on. The small popularity footprint and absent security policy are additional, lesser concerns.

Latest 2.0.16PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful maintenance concern, although the current release and recent push provide partial compensating evidence.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package, creating a transparency concern that the repository may not clearly correspond to this release.

Repo popularitycaution

The repository has only 4 stars, 1 fork, and 11 watchers, indicating limited external adoption; this is supporting caution rather than a health verdict by itself.

Security policycaution

No repository security policy was found, leaving vulnerability-reporting expectations less transparent; the configured security scanning tools provide only partial compensation.

Token permissionscaution

The release workflow has no top-level permissions declaration and relies on job-level permissions, with no read-only workflow identified; explicit least-privilege configuration would be clearer.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Kristoffer Svanmark
Sebastian Thulin

Direct Dependencies

DependencyLast ReleaseScore
helsingborg-stad/wpservice
Version ^2.0
—
—
helsingborg-stad/wputilservice
Version ^0.3
—
—

Weekly Downloads

Info

Last Published
16 days ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform