Package Health

pressbooks/pressbooks-plugin-scaffold

The linked project has tests, release notes, a license, and organization backing. Packagist abandonment, no recent registry releases, and workflow credential-sharing make this a poor default dependency; use only if you control the scaffold.

Latest 0.5.0PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package abandoned, with no replacement listed. This is a substantial adoption and maintenance risk despite evidence of an active source repository.

Release historycaution

The package has eight releases since 2017, but none in the last 12 months and the latest registry release was in January 2024. That weakens confidence in receiving maintained published updates.

Repo commit activitycaution

The repository recorded no commits and no active maintainers in the three months before collection. The later recorded push shows the project is not abandoned outright, but recent development remains thin.

Security policycaution

The repository has no security policy. For a scaffold that may be copied into production plugins, this is a transparency gap, though it is not severe on its own.

Version stabilitycaution

Version 0.5.0 is not a prerelease, but the package remains below a stable major version. This is a modest maturity concern for a scaffold intended to seed new projects.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Book Oven Inc.

Direct Dependencies

DependencyLast ReleaseScore
kucrut/vite-for-wp
Version ^0.5.2
—
—
illuminate/pagination
Version ^8.83
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform