Package Health

pop-wp-schema/posts

This is a healthy, mature release with a strong maintenance record: it has existed for about 5 years, has 151 releases including 33 in the last 12 months, releases roughly every 4 days, and is currently stable and not deprecated. The source repository is active, unarchived, organization-backed, clearly associated with the package, and includes tests, a license, and Composer build tooling. The main concerns are that all 15 commits in the last 3 months came from one contributor, the repository has no security scanning or security policy, and repository popularity is very low; these increase maintainer and transparency risk but do not outweigh the sustained release activity and current repository activity.

Latest 19.2.4PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, which is a concentration risk, but the organization-backed repository and strong release activity provide compensating project context.

Repo bus factorcaution

One contributor made all 15 commits in the last 3 months, creating a genuine continuity risk; organization backing partly mitigates the concern because maintenance can potentially be handed off.

Repo popularitycaution

The repository has only 2 stars, 0 forks, and 1 watcher, indicating limited external adoption; popularity is supporting evidence only and is outweighed here by active releases and recent commits.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tools are configured; the missing scanning lowers supply-chain transparency without indicating an immediate health failure.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Leonardo Losoviz

Direct Dependencies

DependencyLast ReleaseScore
pop-cms-schema/posts-wp
Version ^19.2.4
—
—
pop-wp-schema/customposts
Version ^19.2.4
—
—

Weekly Downloads

Info

Last Published
19 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform