Package Health

johnbillion/query-monitor

Clear documentation, a license, and a security policy make adoption easier. The maintainer base is narrow, but a second active contributor and 67 recent commits provide some continuity.

Latest 4.0.7PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Are you affected? Scan for Free

Health Score Breakdown

Repo bus factorcaution

Commit activity is highly concentrated: one contributor made about 97% of the 67 recent commits. A second active contributor provides some continuity, but the maintainer base remains narrow.

Repo toolingcaution

Composer build tooling is present, but no repository security-scanning tool was detected; the separate security policy and clean workflow audit partly compensate for that gap.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-4267
johnbillion/query-monitor is vulnerable to Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in versions 0.0.0 - 3.20.4.
0.0.0 - 3.20.4
Medium

Package versions

Maintainers

John Blackbourn

Direct Dependencies

DependencyLast ReleaseScore
composer/installers
Version ^1.0 || ^2.0

Weekly Downloads

Info

Last Published
3 months ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform