Package Health

pop-schema/categories

This is a healthy, actively maintained Composer package with a five-year history, 162 releases, 33 releases in the last 12 months, a stable non-prerelease version, current repository activity, clear licensing, tests, and no install-time lifecycle scripts. The main concerns are that all 15 commits in the last three months came from one contributor, the repository has no security scanning or security policy, and the package has very limited public popularity; however, it is backed by an organization-owned repository, matches its repository and README, and is not deprecated or archived. It appears reasonable to depend on, with normal resilience and security-process caveats.

Latest 19.2.4PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, which is a resilience concern in isolation, but the linked repository is organization-owned and shows active commits, providing some project-level backing.

Repo bus factorcaution

All 15 recent commits came from one contributor, creating a genuine continuity risk; organization ownership offers some ability to transfer maintenance, but no second active contributor is shown.

Repo popularitycaution

The repository has only 1 star and no forks or watchers, indicating limited public adoption; popularity is supporting evidence rather than a decisive health criterion, especially given the strong release and commit history.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tools are detected, leaving a security-process gap despite the otherwise standard build setup.

Security policycaution

The repository has no SECURITY policy, reducing transparency about vulnerability reporting and response procedures.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
pop-cms-schema/taxonomies
Version ^19.2.4
—
—

Weekly Downloads

Info

Last Published
19 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform