Package Health

jazzman/wp-performance

wp-performance

Latest v3.6.0PackagistPackagist

67%

Total Score

caution

Usable with caveats: recent maintenance is offset by a single-contributor bus factor and weak workflow pinning.

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access. This is a limited publishing base, although repository activity shows that the same owner is actively maintaining the project.

Project backingcaution

The repository is owned by an individual user rather than an organization, so the single-contributor concentration is not offset by visible organizational backing.

Repo bus factorcaution

All 23 recent commits came from one contributor, leaving maintenance highly concentrated and creating a meaningful continuity risk.

Security policycaution

No repository security policy was found. This is a transparency gap for a plugin whose README describes security hardening, though active scanning provides some compensation.

Workflow auditcaution

Both workflows were fully analyzed with no untrusted checkout or script-injection findings, but all six action references are unpinned and one workflow uses a top-level write token. A high-confidence medium-severity archived action also remains in the release workflow.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Vasyl Sokolyk

Direct Dependencies

DependencyLast ReleaseScore
jazzman/wp-db-pdo
Version ^0.1.6
—
—
composer/installers
Version ^2.3
—
—
jazzman/wp-app-config
Version ^2.3
—
—
jazzman/autoload-interface
Version ^0.3.1
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform