Package Health

pop-cms-schema/post-tag-mutations-wp

This is a mature, actively released and non-deprecated package with 154 releases since 2021, 33 releases in the last 12 months, stable versions, a license file, tests, and no install-time lifecycle scripts. The linked repository is active and organization-owned, but all 14 recent commits came from one contributor, the repository does not name or mention the package despite the package README identifying a monorepo location, and there is no security policy or security-scanning tooling. These concerns warrant caution and verification of repository/package alignment, but the strong release cadence and current maintenance make the package broadly usable rather than unhealthy.

Latest 19.2.4PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, which is a resilience concern in isolation. The organization-owned repository and recent activity provide partial backing, so this is caution rather than danger.

Repo bus factorcaution

One contributor performed all 14 commits in the last 3 months, creating a genuine continuity risk. Organization ownership partly compensates because maintenance can potentially be handed off, but no second active contributor is evidenced.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package. Although the package README claims the source is hosted in a GatoGraphQL monorepo, the collected repository evidence does not verify that relationship, so package/repository alignment should be checked before adoption.

Repo popularitycaution

The repository has zero stars and forks and one watcher, indicating limited public adoption. Popularity is supporting evidence only, so this modestly limits external validation but does not by itself make the package unsafe to depend on.

Repo toolingcaution

Composer is used as a build tool, but no security-scanning tool is detected. The missing scanning coverage is a transparency and defense-in-depth gap, though it is not evidence of maliciousness.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
pop-cms-schema/tag-mutations-wp
Version ^19.2.4
pop-cms-schema/custompost-tags-wp
Version ^19.2.4
pop-cms-schema/custompost-mutations-wp
Version ^19.2.4
pop-cms-schema/custompost-tag-mutations
Version ^19.2.4

Weekly Downloads

Info

Last Published
14 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform