Package Health

wpdev/odata-feed

Documentation, tests, and a clear license make adoption practical. The project is only 92 days old, and most recent commits come from one contributor; workflow dependencies are also unpinned. No security policy is published, leaving maintenance practices less transparent.

Latest 1.0.0PackagistPackagist

66%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Project backingcaution

The repository is owned by an individual user rather than an organization, so the highly concentrated contributor activity has no visible organizational handoff support.

Release historycaution

The package is 92 days old and has only one release, so its maintenance record is still unproven. The repository shows 29 commits in the last three months, which provides some compensating activity.

Repo bus factorcaution

One contributor made 26 of 29 recent commits, or about 90%, so maintenance depends heavily on a single person. Two additional contributors provide limited compensation, but the concentration remains a real continuity concern.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tooling is reported. This is a modest transparency and maintenance gap rather than evidence of an unsafe release by itself.

Security policycaution

The repository has no security policy. That makes vulnerability reporting and response expectations unclear, although it does not by itself show that the package is unmaintained.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

WPDev

Direct Dependencies

DependencyLast ReleaseScore
phpoffice/phpspreadsheet
Version ^1.29
wpdev/phpspreadsheet-odata
Version ^1.0

Weekly Downloads

Info

Last Published
3 months ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform