Package Health

pfefferle/wordpress-activitypub

Version 9.3.1 appears to be a healthy, mature release suitable for dependency use. The package has been maintained since 2018 with 159 releases, 31 releases in the last 12 months, and a stable non-prerelease version. Its linked Automattic-owned repository is active rather than archived, shows substantial recent commit and pull-request activity, includes tests and a changelog even though those are not packaged, and has Composer, Dependabot, CodeQL, and a security policy. The main concern is concentrated recent commit activity: one contributor made about 84% of the last three months' commits, although 12 active contributors and organizational backing materially reduce the bus-factor risk. Workflow permissions are also not explicitly constrained at the top level, but no top-level write permissions or untrusted checkouts were detected.

Latest 9.3.1PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Repo bus factorcaution

One contributor accounts for about 84% of recent commits, creating concentration risk; however, 12 contributors were active and the repository is organization-owned, so this is a caution rather than a severe abandonment concern.

Token permissionscaution

All 10 workflows lack top-level permissions declarations, which weakens least-privilege transparency; nevertheless, no workflow has top-level write permissions and only two rely on job-level permissions.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Matthias Pfefferle

Direct Dependencies

DependencyLast ReleaseScore
composer/installers
Version ^1.0 || ^2.0

Weekly Downloads

Info

Last Published
22 days ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform