Package Health

pop-schema/comments

This is a healthy, actively maintained release with a strong release history, stable versioning, current repository activity, clear licensing, a package structure that matches its documented monorepo component, and no install-time scripts or registry deprecation. The main concerns are that all recent commits come from one contributor, the repository has no security policy or security-scanning tooling, and neither the artifact nor repository provides a changelog; these are meaningful transparency and resilience gaps, though the organization-owned repository and frequent releases reduce abandonment risk. The low popularity is not itself concerning for a focused component package.

Latest 19.2.4PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Package scaffoldingcaution

The artifact includes a substantial README and tests, and the README documents installation, development, testing, analysis, contribution, and security reporting. A changelog is absent both from the package and repository, which is a transparency gap, although the frequent release history partly offsets the concern.

Repo bus factorcaution

One contributor made 100% of the 15 commits in the last 3 months, creating a genuine concentration risk. The organization-owned repository provides some ability to hand maintenance off, but no second active contributor is shown in this signal.

Repo issue activitycaution

There were no new or closed issues and no pull requests in the last month, while the open issue count is unknown. This limits evidence from issue handling, but does not outweigh the package's active release and commit history.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools are reported. The missing scanning coverage is a security-process gap, though it is not evidence of maliciousness or an immediate health verdict.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
pop-cms-schema/customposts
Version ^19.2.4
—
—

Weekly Downloads

Info

Last Published
19 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform