Package Health

wpmetabox/mb-comment-meta

Tests, a useful README, and organization backing reduce adoption risk. Maintenance has gone quiet since the last release, and the workflows use unpinned actions; pin this version if you adopt it.

Latest 1.0.2PackagistPackagist

64%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The package has had only two releases, with no release in the last 12 months; the latest release was about 22 months ago. This is a meaningful maintenance concern, though the package is not deprecated and remains on a stable major version.

Repo commit activitycaution

There were no commits and no active maintainers in the past three months. This supports the concern that maintenance has slowed, although the repository was pushed more recently than the package's last registry release.

Repo toolingcaution

The project uses Composer for its build process, but no security scanning tools were detected. The missing scanning is a modest transparency and hygiene gap rather than a severe dependency risk.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a hygiene concern, not evidence that the package is unsafe.

Workflow auditcaution

Both analyzed workflows use unpinned actions, which weakens build reproducibility. The audit found no dangerous triggers, untrusted checkouts, script injection, or excessive top-level permissions, which limits the impact.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Tran Ngoc Tuan Anh

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
1 year ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform