Package Health

pop-schema/post-tag-mutations

This release appears healthy and suitable to depend on: it has a long release history, frequent recent releases, a stable non-prerelease version, an active and non-archived source repository, explicit GPL licensing, coherent package contents, and no install-time lifecycle scripts. The main concerns are that all 15 recent commits came from one contributor, the repository has no security scanning or security policy, and the repository has very little public popularity; however, the organization-owned repository and strong ongoing release activity provide meaningful maintenance backing. Overall, this is a well-maintained package with moderate transparency and contributor-concentration risks rather than a clear abandonment concern.

Latest 19.2.4PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Repo bus factorcaution

One contributor made 100% of the 15 recent commits, creating a genuine continuity risk. This is partly mitigated because the repository is owned by the PoPCMSSchema organization, which can provide maintenance handoff capacity.

Repo popularitycaution

The repository has only 1 star, 0 forks, and 1 watcher, so independent adoption evidence is limited. Low popularity is supporting caution rather than a health verdict because release and commit activity are strong.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools are reported. This leaves a security-hygiene gap, although it is not evidence of malicious behavior or abandonment.

Security policycaution

No repository security policy was found, reducing vulnerability-reporting transparency. The README does provide a security contact, which partially compensates for the repository-level gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
pop-cms-schema/post-tags
Version ^19.2.4
—
—
pop-cms-schema/tag-mutations
Version ^19.2.4
—
—
pop-cms-schema/post-mutations
Version ^19.2.4
—
—
pop-cms-schema/custompost-tag-mutations
Version ^19.2.4
—
—

Weekly Downloads

Info

Last Published
19 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform