Package Health

pop-schema/comments-wp

This is a generally healthy and actively maintained package: it has over five years of release history, 162 releases including 33 in the last 12 months, a stable non-prerelease version, a current non-archived repository, matching package documentation, tests, and recent commit activity. The main concerns are that all 14 recent commits came from one contributor, the repository has minimal popularity, and it lacks a security policy and security-scanning tooling; the organization-owned repository and sustained release cadence reduce but do not eliminate those risks. The absent changelog is a documentation gap, but the package otherwise presents clear licensing, source, build, and usage information.

Latest 19.2.4PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, which is a concentration concern; however, this is partly compensated by the linked repository being owned by an organization and by the package's sustained release activity.

Repo bus factorcaution

One contributor made all 14 commits in the last 3 months, creating a genuine continuity risk. The organization-owned repository provides some ability to transfer maintenance, so this is caution rather than severe risk.

Repo issue activitycaution

There were no new or merged pull requests and no new or closed issues in the last month; this is limited evidence of community interaction, though it does not outweigh the package's active release and commit cadence.

Repo popularitycaution

The repository has only 1 star, 0 forks, and 1 watcher. This is weak supporting evidence of adoption, but popularity alone is not decisive for a small specialized package.

Repo toolingcaution

Composer is used as a build tool, which is appropriate for this PHP package, but no security-scanning tools are reported; the missing scanning is a supply-chain hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
pop-cms-schema/comments
Version ^19.2.4
—
—
pop-cms-schema/customposts-wp
Version ^19.2.4
—
—

Weekly Downloads

Info

Last Published
19 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform