Package Health

pop-schema/post-tags

This is a healthy, actively maintained release with a substantial history: 161 releases over roughly 5 years, 33 releases in the last 12 months, and a latest release published at assessment time. The package is stable, licensed, non-deprecated, linked to an active organization-owned repository, and includes a README, tests, source files, and Composer build tooling. The main concerns are that all 15 commits in the last 3 months came from one contributor and the repository has no formal security policy or security-scanning tooling; these are meaningful resilience and transparency gaps, but they are partly offset by the organization backing, ongoing release cadence, repository activity, and clear package-to-repository alignment.

Latest 19.2.4PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Repo bus factorcaution

One contributor made all 15 commits in the last 3 months, creating a genuine continuity risk; organization ownership partly compensates because maintenance can potentially be handed off within the project.

Repo issue activitycaution

There were no new issues or pull requests in the last month and no merged pull requests; this provides little evidence of community engagement, but it is not by itself evidence of abandonment because commits and releases remain active.

Repo popularitycaution

The repository has only 1 star and no forks, so external adoption evidence is weak; however, popularity is supporting evidence and does not outweigh the package's strong release and commit activity.

Repo toolingcaution

Composer is used as a build tool, but no security-scanning tools are configured. The build tooling is healthy, while the missing scanning coverage is a modest transparency and supply-chain hygiene gap.

Security policycaution

The repository has no formal security policy, leaving vulnerability-reporting and response expectations less explicit despite the README providing an email-based security contact.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
pop-cms-schema/tags
Version ^19.2.4
—
—
pop-cms-schema/posts
Version ^19.2.4
—
—

Weekly Downloads

Info

Last Published
19 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform