Package Health

pop-schema/custompost-tags-wp

This is a healthy, actively maintained Composer package with a long release history, 154 releases since 2021, 33 releases in the last 12 months, and a recent stable release. The linked organization-owned repository is not archived, matches the package, and explicitly documents the package; licensing, README coverage, tests, build tooling, and dependency scope are also solid. The main concerns are that all 14 recent commits came from one contributor, there is no changelog or repository security policy, and repository popularity is very low, but these are mitigated by ongoing release and commit activity and organization backing. It appears reasonable to depend on, subject to normal review of its small contributor base and limited security-process transparency.

Latest 19.2.4PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry publishing maintainer is listed, which is a limited publishing base. However, this is less concerning because the linked repository is owned by an organization and the package shows substantial ongoing release activity.

Repo bus factorcaution

All 14 commits in the last 3 months came from one contributor, creating a concentrated operational dependency. Organization ownership provides some potential handoff capacity, but no second active contributor is observed.

Repo popularitycaution

The repository has only 2 stars, 0 forks, and 1 watcher, indicating limited public adoption or visibility. Popularity is supporting evidence rather than a decisive health measure, and active releases compensate for much of this concern.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The missing scanning automation is a process gap, although it is not by itself evidence of poor package health.

Security policycaution

The linked repository has no SECURITY.md or other detected security policy, reducing transparency about vulnerability reporting and response procedures.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
pop-cms-schema/tags-wp
Version ^19.2.4
pop-cms-schema/customposts-wp
Version ^19.2.4

Weekly Downloads

Info

Last Published
15 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform