Package Health

lipemat/wp-phpcs

This is a mature, actively maintained and clearly identified package: it has been released since 2017, has 56 releases including 8 in the last 12 months, is stable, not deprecated, and its repository was updated very recently. The artifact is licensed, has substantial documentation, and corresponds directly to a repository with extensive tests and build tooling, while the package has no install-time lifecycle scripts. The main concerns are that all 14 commits in the last 3 months came from one contributor, the repository has no security policy, and its sole workflow lacks top-level token permissions; these reduce resilience and security transparency but do not outweigh the strong maintenance and provenance evidence.

Latest 4.7.3PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Project backingcaution

The repository is owned by a user rather than an organization, so the concentrated maintainer activity is not mitigated by visible organizational backing.

Repo bus factorcaution

One contributor made all 14 commits in the last 3 months, creating a genuine single-maintainer continuity risk for a user-owned project.

Repo toolingcaution

Composer build tooling is present, supporting reproducible project management, but no security scanning tools were detected, leaving a modest security-process gap.

Security policycaution

The repository has no security policy, reducing vulnerability-reporting transparency and maintainer guidance for security issues.

Token permissionscaution

The sole workflow lacks top-level token permissions declarations. Although no top-level write permissions were observed, explicit least-privilege configuration would provide stronger CI security hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

lipemat

Direct Dependencies

DependencyLast ReleaseScore
automattic/vipwpcs
Version ^3.0.1
—
—
wp-coding-standards/wpcs
Version ^3.4.1
—
—
phpcsstandards/phpcsextra
Version ^1.0.2
—
—
squizlabs/php_codesniffer
Version ^3.13.2
—
—
sirbrillig/phpcs-variable-analysis
Version ^2.12.0
—
—

Weekly Downloads

Info

Last Published
20 days ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform