Package Health

wpcloud/wp-stateless

Healthy and suitable to use, with a thin recent contributor base as the main caveat. It has a long release history, releases roughly every 10 days, an active unarchived repository, and clear security and build practices.

Latest 4.4.3PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Are you affected? Scan for Free

Health Score Breakdown

Repo bus factorcaution

The top contributor made all 5 commits in the last 3 months, leaving no demonstrated second active contributor. Organization backing provides some handoff capacity, but the recent activity is still concentrated.

Repo commit activitycaution

There were 5 commits in the last 3 months, showing recent activity, but all activity came from only one active maintainer.

Repo issue activitycaution

The repository still merges pull requests, with 4 merged in the last month and 2 issues closed, although there were no new issues or pull requests during that period and 61 issues remain open.

Token permissionscaution

One workflow declares write permissions for publishing, which is consistent with a release workflow, but the security-scan workflow lacks top-level permissions and is less explicit than ideal.

Vulnerabilities

TitleVersionsSeverity
CVE-2022-4905
wpcloud/wp-stateless is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.2.0.
0.0.0 - 3.2.0
Medium

Package versions

Maintainers

UDX

Direct Dependencies

DependencyLast ReleaseScore
firebase/php-jwt
Version ^6.1.2
—
—
ccampbell/chromephp
Version ^4.1
—
—
composer/installers
Version ~2.3
—
—
udx/lib-wp-bootstrap
Version ^1.3
—
—
udx/lib-ud-api-client
Version ^1.2
—
—

Weekly Downloads

Info

Last Published
20 days ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform