Package Health

wp-oop/containers

Release notes, repository tests, and recent work provide useful maintenance evidence. MIT licensing, a small dependency set, and organization ownership help, but the alpha status limits confidence.

Latest v0.2.0-alpha1PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package has six releases since February 2021, with only two in the last 12 months and a median interval of about 323 days. This indicates a slow release cadence rather than abandonment, so it is a modest maintenance concern.

Repo bus factorcaution

One contributor made all 11 commits in the last three months. Organization ownership provides some handoff capacity, but no second recently active contributor is shown, leaving maintenance continuity exposed.

Security policycaution

The repository has no documented security policy. This is a transparency gap for reporting vulnerabilities, though the available Psalm scanning provides some compensating security practice.

Version stabilitycaution

The assessed version is a prerelease, and all recent releases are prereleases. That signals an immature API and higher change risk for consumers.

Workflow auditcaution

The single workflow was fully analyzed with no audit findings, dangerous triggers, untrusted checkouts, or script injection. Both action references are unpinned, so their contents can change unexpectedly and create a modest supply-chain hygiene concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Anton Ukhanev

Direct Dependencies

DependencyLast ReleaseScore
psr/container
Version ^2.0
—
—
dhii/collections-interface
Version ^0.5.0-beta1
—
—

Weekly Downloads

Info

Last Published
2 months ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform