Package Health

pop-api/api-graphql

This is a mature, actively released and currently maintained package: it has 163 releases over roughly 5 years, 33 releases in the last 12 months, a stable non-prerelease version, and a repository pushed on the assessment date. The package is licensed, includes a README and tests in both the artifact and repository, has a small runtime dependency profile, and has no install lifecycle scripts or registry deprecation. The main concerns are that all 14 commits in the last 3 months came from one contributor, the repository has very low popularity, and it has no security policy or security-scanning tooling; these reduce resilience and transparency but do not outweigh the strong release and maintenance evidence, particularly with organization ownership and package-repository alignment.

Latest 19.2.4PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access. This is a limited publishing base, but the repository is owned by an organization and release activity is strong, so it is a resilience concern rather than a severe health risk.

Repo bus factorcaution

One contributor made all 14 commits in the last 3 months, creating a genuine continuity risk. Organization ownership offers some potential handoff capacity, but no second active contributor is shown by this signal.

Repo popularitycaution

The repository has only 3 stars, 0 forks, and 1 watcher. Low popularity is not decisive for a specialized package, but it provides little supporting evidence of broad external adoption.

Repo toolingcaution

Composer is used as the build tool, but no security-scanning tools are detected. Build tooling is appropriate, while the missing scanning is a modest security-hygiene gap.

Security policycaution

No repository security policy was found, reducing vulnerability-reporting transparency. This is a hygiene concern, not evidence that the package is unsafe or abandoned.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
pop-api/api-mirrorquery
Version ^19.2.4
—
—

Weekly Downloads

Info

Last Published
17 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform