Package Health

pop-cms-schema/menus

This is a generally healthy and actively maintained release: the package has existed since 2021, has 162 releases including 33 in the last 12 months, is on a stable major version, is not deprecated, and its linked organization-owned repository is active and correctly associated with the package. The main concerns are that all 15 commits in the last three months came from one contributor, the repository has very low popularity, no security scanning or security policy is present, and no changelog was detected. These issues warrant normal dependency review and monitoring, but the strong release cadence, recent repository activity, licensing, tests, and lack of install-time scripts make the package suitable to depend on.

Latest 19.2.4PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Repo bus factorcaution

One contributor made all 15 commits in the last three months, creating a real concentration risk. The organization-owned repository provides some ability to hand off maintenance, but no second active contributor is shown.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, and no pull requests were open. This provides little evidence of community activity, though it is not by itself evidence of abandonment.

Repo popularitycaution

The repository has only 1 star, 0 forks, and 1 watcher. This is weak supporting evidence and limits external validation, although low popularity alone does not establish poor maintenance.

Repo toolingcaution

Composer is used as a build tool, but no security-scanning tools are detected. The missing scanning coverage is a security-process hygiene gap, not a health verdict on the package itself.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
getpop/engine
Version ^19.2.4
pop-cms-schema/taxonomies
Version ^19.2.4

Weekly Downloads

Info

Last Published
15 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform