Package Health

pop-cms-schema/taxonomyquery

This is a healthy, actively released package with a substantial history: 162 releases over about 5.6 years, 33 releases in the last 12 months, and a current stable version. It is not deprecated or archived, has clear GPL licensing, repository-backed documentation and tests, and no install-time lifecycle scripts. The main concerns are that all 14 recent commits came from one contributor, the repository has no security-scanning tooling or security policy, and the repository is very small with limited popularity; however, organization ownership, frequent releases, and an explicit repository/package match provide meaningful backing and reduce abandonment risk.

Latest 19.2.4PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Repo bus factorcaution

One contributor made 100% of the 14 commits in the last 3 months, creating a genuine single-maintainer continuity risk. Organization ownership provides some ability to hand off maintenance, but no second active contributor is shown.

Repo issue activitycaution

There were no new or closed issues and no pull-request activity in the last month, while open pull requests are zero. This does not show a problem by itself, but it provides little evidence of an active external maintenance community.

Repo popularitycaution

The repository has only 1 star and no forks, indicating limited external adoption or review. Popularity is supporting evidence rather than a decisive health criterion, so this is a modest concern.

Repo toolingcaution

Composer is used as a build tool, but no security-scanning tools are reported. The missing scanning layer is a hygiene gap, though it is not by itself evidence that the package is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
getpop/engine
Version ^19.2.4
—
—

Weekly Downloads

Info

Last Published
19 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform