Package Health

pop-schema/post-category-mutations-wp

This is a generally healthy and actively maintained release: it has a long history, 154 releases including 33 in the last 12 months, a stable non-prerelease version, an active non-archived repository, and recent commits. The main risks are concentrated maintenance—14 commits from one contributor in the last 3 months—and limited repository transparency, including no security policy, no changelog, and no repository README reference to the exact package. Organization ownership and the package's tests, license, Composer tooling, and lack of install-time scripts partly compensate for those concerns, making it usable but worth monitoring for maintainer continuity.

Latest 19.2.4PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, which is a concentration concern in isolation. The repository is organization-owned, making a short registry maintainer list more understandable, but it does not remove the continuity risk.

Package file treecaution

The artifact and repository have matching, compact file trees containing source code, configuration, a license, README, and tests, which supports reproducible package structure. The only test file is named ModuleTestDisabled.php, so test coverage should not be assumed to be comprehensive.

Repo bus factorcaution

One contributor made 100% of the 14 commits in the last 3 months, creating a genuine bus-factor concern. Organization ownership provides some potential handoff capacity, but no second active contributor is evidenced.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package, so the linkage is less transparent and the package may not be directly represented by that repository. The README nevertheless identifies the broader GatoGraphQL monorepo as the source location, which provides partial context but does not fully resolve the mismatch.

Repo popularitycaution

The repository has no stars or forks and only one watcher, indicating limited external adoption or visibility. Popularity is supporting evidence rather than a verdict, so this is a modest concern rather than a severe health risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
pop-cms-schema/category-mutations-wp
Version ^19.2.4
pop-cms-schema/custompost-mutations-wp
Version ^19.2.4
pop-cms-schema/custompost-categories-wp
Version ^19.2.4
pop-cms-schema/custompost-category-mutations
Version ^19.2.4

Weekly Downloads

Info

Last Published
16 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform