Package Health

soderlind/virtual-media-folders

Clear documentation, tests, release notes, and a small dependency set support adoption. A single active contributor, no security policy, and several unpinned workflow actions leave continuity and build-hygiene risks.

Latest 2.1.5PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Project backingcaution

The registry namespace and repository owner both identify the same individual account, and the repository is user-owned. This confirms ownership alignment but provides no organizational backing to offset the concentrated bus factor.

Repo bus factorcaution

One contributor made all 9 commits in the last 3 months, representing a 100% top-contributor share. The project is user-owned rather than organization-owned, so this concentration is a real continuity risk.

Security policycaution

No repository security policy was found. For a WordPress plugin, the absence of a documented vulnerability-reporting process reduces transparency and response confidence.

Workflow auditcaution

All 4 workflows were analyzed successfully with no reported audit findings, no untrusted checkouts, and no script injection; three scope permissions at job level and one use read-only permissions. However, 6 of 10 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Per Soderlind

Direct Dependencies

DependencyLast ReleaseScore
composer/installers
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
10 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform