Package Health

pop-api/api-clients

This is a mature, actively released package with 163 releases since January 2021, 33 releases in the last 12 months, a stable non-prerelease version, no registry deprecation, a non-archived repository, explicit licensing, tests in both the artifact and repository, and no install-time lifecycle scripts. The package is transparently tied to its matching repository and an organization-owned project, with 15 recent commits, although all recent activity comes from one contributor and the repository has limited popularity and no security scanning or security policy. It appears reasonable to depend on, with maintainer concentration and security-process gaps worth monitoring.

Latest 19.2.4PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Repo bus factorcaution

All 15 recent commits came from one contributor, creating genuine continuity risk. Organization ownership provides some ability to hand maintenance off, but no second active contributor is shown to compensate for the concentration.

Repo issue activitycaution

There were no new or merged pull requests and no new or closed issues in the last month; this is ambiguous because open issue data is unavailable, so it is only a mild maintenance concern.

Repo popularitycaution

The repository has only 2 stars, 0 forks, and 1 watcher. This is supporting evidence of a small project, but does not outweigh the package's sustained release and commit activity.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are reported. The missing scanning is a process gap, though it is not by itself evidence of unsafe code.

Security policycaution

The linked repository has no SECURITY policy. The README provides a security contact, which partly compensates for the missing formal policy, but the repository's security process remains less explicit.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
pop-api/api-endpoints
Version ^19.2.4
—
—

Weekly Downloads

Info

Last Published
20 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform