Package Health

pop-cms-schema/user-state-mutations

This is a healthy, mature release with a five-year history, 162 releases, 33 releases in the last 12 months, and a short median release interval of about 4 days. It is a stable major release, not deprecated, licensed under GPL-2.0-or-later, includes a README and license, has repository tests and Composer build tooling, and was pushed very recently. The main concerns are that all 15 recent commits came from one contributor, the repository has no security scanning or security policy, and repository popularity is minimal; however, the organization-owned repository and sustained release activity provide meaningful backing and reduce abandonment risk. It appears reasonable to depend on, subject to normal review of its runtime dependencies and security-sensitive user-authentication behavior.

Latest 19.2.4PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Repo bus factorcaution

Recent activity is fully concentrated in one contributor, creating a genuine bus-factor concern; organization ownership and continued recent commits partially compensate but do not remove the concentration risk.

Repo issue activitycaution

There were no new or merged pull requests in the last month and issue counts are partly unknown, so issue-management evidence is limited; this is tempered by the package's active release history.

Repo popularitycaution

The repository has zero stars and forks and one watcher, indicating little public adoption evidence; popularity is supporting evidence only, and the strong release and commit history is more informative here.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools are detected; the missing scanning is a hygiene gap rather than evidence of abandonment.

Security policycaution

The repository has no SECURITY.md policy, reducing transparency around vulnerability reporting; the README does provide a security contact, which partially compensates.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
pop-cms-schema/user-state
Version ^19.2.4

Weekly Downloads

Info

Last Published
14 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform