Package Health

pop-api/api-endpoints-for-wp

This is a healthy, actively maintained Composer package with a release history dating to 2021, 163 releases, 33 releases in the last 12 months, and a current stable version. The artifact is licensed, includes a README and tests, has no install-time lifecycle scripts, is not deprecated or archived, and is backed by an organization-owned repository that clearly matches the package. The main risks are concentrated maintenance: one contributor made all 14 commits in the last three months, the repository has very little public popularity, and it lacks a security policy and security-scanning tooling. These concerns warrant monitoring but do not outweigh the strong release cadence, current repository activity, and package hygiene.

Latest 19.2.4PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, which is a modest publishing-resilience concern; however, the linked repository is organization-owned, providing some backing beyond the registry account.

Repo bus factorcaution

One contributor made all 14 commits in the last 3 months, creating a genuine continuity risk; organization ownership provides some potential handoff capacity but does not remove the observed concentration.

Repo popularitycaution

The repository has only 2 stars, 0 forks, and 1 watcher. This limits popularity-based supporting evidence but is not itself evidence that a small package is unsafe to depend on.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools are configured. The missing scanning is a security-process gap, though it is not by itself evidence of poor maintenance.

Security policycaution

No repository security policy was found, leaving vulnerability-reporting guidance less transparent than ideal.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
pop-api/api-endpoints
Version ^19.2.4

Weekly Downloads

Info

Last Published
17 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform