Package Health

humanmade/cms

Documentation, tests, release notes, and automated dependency scanning provide useful support. Migrate to altis/cms and audit the release workflows before adopting this package.

Latest 28.0.2PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Registry deprecationdanger

The registry marks the entire package as abandoned and names altis/cms as its replacement, which is a substantial adoption and continuity risk despite recent activity.

Security policycaution

The repository has no published security policy, leaving disclosure and response expectations unclear.

Workflow auditcaution

All seven action references are unpinned, and two high-confidence template-injection findings plus one adhoc package installation were reported; the pull_request_target workflow has no untrusted checkout or script-injection finding, so this is workflow hygiene risk rather than a standalone severe verdict.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Human Made

Direct Dependencies

DependencyLast ReleaseScore
roots/wordpress
Version 7.1.1
altis/cms-installer
Version ^0.4.4
humanmade/clean-html
Version ^2.0.0
humanmade/asset-loader
Version ^1.0.2
stuttter/wp-user-signups
Version ^5.0.2

Weekly Downloads

Info

Last Published
3 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform