Package Health

rwsite/wp-thumbnail-plugin

The project is young and lightly adopted, with one registry maintainer and two repository stars. It has clear documentation, tests, a changelog, and a recent release, which support a bounded trial.

Latest 1.0.3PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Maintainerscaution

Only one account has registry publish access, limiting publishing redundancy. The linked repository is user-owned rather than organization-backed, so there is no visible organizational compensation.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, despite a recent package release. That weakens evidence of ongoing maintenance.

Repo popularitycaution

The repository has only 2 stars, 2 forks, and 1 watcher, providing little evidence of broad external review or adoption. Low popularity is supporting evidence, not proof of poor quality.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a moderate transparency gap for a WordPress plugin.

Workflow auditcaution

All five analyzed action references are unpinned, which leaves the build exposed to changing action contents. The workflow has no untrusted checkout or script-injection findings, so this is a hygiene concern rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Aleksei Tikhomirov

Direct Dependencies

DependencyLast ReleaseScore
composer/installers
Version ^2.2

Weekly Downloads

Info

Last Published
1 day ago
Created
8 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform