Package Health

popphp/popphp-skeleton

The BSD-3-Clause license and organization-backed repository provide clear ownership and reuse terms. Maintenance is concentrated in one contributor, with no security policy; use Pop PHP Framework v7 through the kettle CLI for new applications.

Latest 4.0.5PackagistPackagist

18%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

63

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Using this package? Scan for Free

Health Score Breakdown

Package scaffoldingdanger

The README and exact-version release notes explicitly mark the project as end of life and direct users to Pop PHP Framework v7, which outweighs the otherwise useful documentation.

Release historycaution

The package has existed since 2015 with 18 releases, but only two releases in the last 12 months and a median interval of about eight months indicate a modest maintenance cadence.

Repo bus factorcaution

All recent commit activity comes from one contributor, leaving maintenance dependent on a single person; organization backing provides some handoff capacity but no second active contributor is shown.

Repo commit activitycaution

Only one commit was recorded in the last three months, showing limited recent development activity even though the repository was updated recently.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for consumers.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Nick Sagona

Direct Dependencies

DependencyLast ReleaseScore
popphp/popphp
Version ^4.4.0
—
—
popphp/pop-http
Version ^5.3.8
—
—
popphp/pop-view
Version ^4.0.4
—
—
popphp/pop-kettle
Version ^2.3.4
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform