Package Health

jazzman/wp-boilerplate

This is a generally usable and actively published stable package with a clear MIT license, a substantial and coherent source tree, a matching repository, changelog, release automation, and no deprecation or archive signal. However, adoption carries moderate maintenance and transparency risk: the package has only eight releases over nearly seven years, no tests in either the artifact or repository, very low repository adoption, unresolved pull requests with no recent issue or PR progress, a relatively large runtime dependency surface, and a workflow without explicit top-level token permissions. The package appears suitable for use with normal dependency and release monitoring, but it is not as strongly validated or broadly maintained as a mature foundational dependency.

Latest v3.1.1PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dependency profilecaution

Fifteen runtime dependencies create a meaningful transitive maintenance and supply-chain surface for a project scaffold, though the declared dependencies are consistent with its broad WordPress stack functionality.

Lifecycle scriptscaution

The package uses a post-root-package-install script, which adds installation complexity and execution surface, although this is consistent with a Composer project scaffold rather than inherently unhealthy.

Package scaffoldingcaution

A substantial README and changelog are present, and the repository uses GitHub Releases; the absence of tests is a genuine validation gap for this application scaffold.

Project backingcaution

The repository is owned by a personal user account rather than an organization, so there is limited evidence of institutional backing or a broad continuity plan.

Release historycaution

The package has existed for about 6 years and 9 months, with releases in the last 12 months, but only eight releases overall and a median interval of about 118 days indicate a relatively modest release cadence.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Scott Walkinshaw
Ben Word
Vasyl Sokolyk

Direct Dependencies

DependencyLast ReleaseScore
oscarotero/env
Version ^2.1
—
—
jazzman/wp-mail
Version ^2.0
—
—
roots/wordpress
Version ^6.9
—
—
roots/wp-config
Version ^1.0
—
—
vlucas/phpdotenv
Version ^5.5
—
—

Weekly Downloads

Info

Last Published
24 days ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform