Package Health

pocketmine/pocketmine-mp

Unfit to use despite strong history and recent releases: the package is deprecated on Packagist and its source repository is archived. The repository still has tests, release notes, and recent activity, but those do not offset the risk that this release is no longer supported.

Latest 5.44.3PackagistPackagist

20%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Are you affected? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no replacement specified. Package-level deprecation is a severe adoption risk even though recent releases exist.

Repository archiveddanger

The linked source repository is archived, which strongly indicates that normal maintenance and issue handling have stopped. Its last push was on July 9, 2026, but archival status outweighs that recent activity.

Dangerous workflowscaution

Three workflows use pull_request_target, which warrants review because that trigger can expose privileged workflow context. The analysis found no untrusted checkouts or script injection, so this is not a severe workflow finding.

Repo bus factorcaution

One contributor made 11 of 12 recent commits, leaving maintenance highly concentrated. The organization backing provides some handoff capacity, but the concentration remains a concern, especially alongside archival.

Repo commit activitycaution

The repository recorded 12 commits from 2 active maintainers in the last 3 months, showing recent work rather than complete inactivity. However, this activity conflicts with the repository's archived state and is too limited to offset it.

Vulnerabilities

TitleVersionsSeverity
CVE-2023-7332
pocketmine/pocketmine-mp is vulnerable to Security Vulnerability in versions 0.0.0 - 4.18.1.
0.0.0 - 4.18.1
High

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
ramsey/uuid
Version ~4.9.0
—
—
pocketmine/log
Version ^0.4.0
—
—
pocketmine/nbt
Version ~1.2.0
—
—
pocketmine/math
Version ~1.0.0
—
—
pocketmine/color
Version ^0.3.0
—
—

Weekly Downloads

Info

Last Published
3 months ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform