Package Health

wpdesk/wp-migrations

This is a generally healthy, usable dependency with clear licensing, a substantial README and changelog, stable releases, a matching organization-owned repository, repository tests and build tooling, and no deprecation or dangerous workflow findings. The main concerns are that the repository shows no commits or active maintainers in the last 3 months, has no security policy or security-scanning tools, and its GitHub Actions workflow does not declare top-level permissions; these reduce transparency and maintenance confidence but are not sufficient to make the package unfit, especially given the release published on the assessment date and the repository's complete source scaffolding.

Latest 1.2.1PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo commit activitycaution

The repository records 0 commits and 0 active maintainers in the last 3 months, which is a genuine maintenance concern, although the latest release and repository push occurred on the assessment date.

Repo issue activitycaution

There are no open issues or pull requests and no recent issue or pull-request activity. This is neutral-to-ambiguous for a small package, but offers little evidence of an active user or maintainer community.

Repo popularitycaution

The repository has zero stars, forks, and watchers, which provides no external adoption evidence; this is a supporting gap rather than a decisive health problem for a small specialized library.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools are configured, leaving a modest security-process and transparency gap.

Security policycaution

The repository has no security policy, so vulnerability-reporting expectations and disclosure handling are not documented.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

WP Desk
Octolize

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1
wpdesk/wp-mutex
Version ^1.1 | ^2
wpdesk/wp-notice
Version ^3.3

Weekly Downloads

Info

Last Published
15 days ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform