Package Health

pop-schema/post-tags-wp

This is a healthy, actively released package with a strong maintenance history: it has existed since 2021, has 162 releases including 33 in the last 12 months, is not deprecated, and the current stable release was pushed very recently. The package is clearly licensed, has README and test coverage in the source repository, uses Composer, and has no install-time lifecycle scripts. The main concerns are a single active contributor with all recent commits, low repository adoption, and no declared security policy or security-scanning tooling; however, the repository is organization-owned and clearly matches the package, which provides meaningful project backing and transparency. Overall, it appears reasonable to depend on, with some maintainer-concentration and security-process risk.

Latest 19.2.4PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, which is a concentration concern, although registry access alone does not establish actual project maintenance capacity.

Repo bus factorcaution

One contributor made all 14 commits in the last 3 months, creating a genuine continuity risk. Organization ownership provides some ability to hand off maintenance, but no second active contributor is evidenced.

Repo issue activitycaution

There were no new issues or pull requests in the last month, and issue totals are unavailable. This provides little evidence of community activity, but does not outweigh the package's frequent release history.

Repo popularitycaution

The repository has only 1 star and 0 forks, so independent adoption evidence is limited; this is supporting caution rather than a health verdict by itself.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools are configured, leaving a security-process gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
pop-cms-schema/post-tags
Version ^19.2.4
pop-cms-schema/custompost-tags-wp
Version ^19.2.4

Weekly Downloads

Info

Last Published
14 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform