Package Health

pollen/query

Usable with caveats: the package is licensed, documented, tested, actively released, and backed by a matching organization repository. Recent repository activity is quiet, and the project lacks security-policy and explicit workflow-token safeguards.

Latest 1.0.3PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Maintainerscaution

A single registry publishing account is listed, which limits registry-level redundancy; however, the package is backed by an organization-owned repository, making a short registry maintainer list less concerning.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers over the last three months. This is a meaningful maintenance concern, though the same-day push and current release provide some compensating evidence.

Repo issue activitycaution

There is one open issue and no issue or pull-request activity in the last month, suggesting limited community activity without showing a severe unresolved maintenance problem.

Repo popularitycaution

The repository has 18 stars, three watchers, and no forks. This is modest adoption and offers little independent evidence of maturity, but popularity is only supporting evidence.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. The build setup is established, while automated security coverage is limited.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Olivier Gorzalka

Direct Dependencies

DependencyLast ReleaseScore
pollora/wordpress-args
Version ^1.1

Weekly Downloads

Info

Last Published
5 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform