Package Health

mediawiki/opensearch-query

Usable with caveats: the repository is active, identifiable, licensed, and has clear installation documentation, but this is a very new package with only one release and a small, concentrated contributor base. The lack of a security policy adds a transparency gap.

Latest 1.0.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Project backingcaution

The repository is owned by an individual user rather than an organization, so the small maintainer base and concentrated recent activity represent the actual observed continuity of the project.

Release historycaution

This release is from a package only 27 days old with one release and no established release cadence, so its maturity and long-term maintenance are not yet demonstrated.

Repo bus factorcaution

Two contributors are active, which provides some continuity, but one contributor accounts for 80% of recent commits, leaving maintenance somewhat concentrated.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tools are configured; this is a modest transparency and maintenance gap rather than evidence of abandonment.

Security policycaution

The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities in an extension that connects to OpenSearch.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Toniher

Direct Dependencies

DependencyLast ReleaseScore
composer/installers
Version >=1.0.1

Weekly Downloads

Info

Last Published
1 month ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform