Package Health

pop-schema/queriedobject-wp

This is a healthy, actively maintained release with a substantial history: 161 releases over roughly 5 years, 33 releases in the last 12 months, and a latest release published at assessment time. The package is stable, not deprecated, licensed, directly backed by an organization-owned repository, and has matching source, tests, and documented development practices. The main concerns are maintenance concentration in one active contributor, no repository security policy or security-scanning tooling, and very low repository popularity, although the organization's backing and frequent releases substantially reduce abandonment risk. Overall, it appears reasonable to depend on, with normal supply-chain review and monitoring recommended.

Latest 19.2.4PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Repo bus factorcaution

One contributor made all 14 commits in the last 3 months, creating a genuine concentration and continuity risk. The organization-owned repository and frequent release history partly mitigate the risk but do not remove it.

Repo popularitycaution

The repository has zero stars and forks and only one watcher. This limits popularity-based corroboration, but popularity is supporting evidence and does not outweigh the package's strong release and commit activity.

Repo toolingcaution

Composer is used as a build tool, supporting a standard reproducible package workflow, but no security-scanning tools are configured. The missing scanning is a hygiene gap rather than evidence of abandonment.

Security policycaution

The repository has no SECURITY.md or other detected security policy. The README provides a security contact, which offers some disclosure guidance, but the repository-level policy gap remains.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
pop-cms-schema/queriedobject
Version ^19.2.4
—
—
pop-cms-schema/schema-commons-wp
Version ^19.2.4
—
—

Weekly Downloads

Info

Last Published
17 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform