Package Health

yard/wp-database

yard/wp-database v2.0.0 appears suitable to depend on, with a stable major release, recent publication, an unarchived repository, organizational backing, tests, documented workflows, and evidence of recent pull-request activity. The main concerns are a small recent release history, only two commits from one active maintainer in the last three months, limited repository popularity, absent security policy, and broadly undeclared GitHub Actions permissions; these reduce resilience and transparency but do not indicate abandonment or an otherwise unfit release.

Latest v2.0.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dependency profilecaution

Six runtime dependencies create a meaningful dependency surface, including framework and data packages, but this is proportionate to a WordPress Eloquent ORM integration and is not excessive on its own.

Lifecycle scriptscaution

A post-autoload-dump install-time script is present. This is a legitimate Composer integration point but increases installation complexity and warrants review because it executes during dependency installation.

Repo bus factorcaution

One contributor made 100% of the two commits in the last three months, creating a concentrated bus factor. Organizational ownership provides some ability to hand maintenance off, but no second active contributor is shown.

Repo commit activitycaution

Only two commits were recorded in the last three months, with one active maintainer. Recent repository activity exists, but the low volume suggests a small maintenance capacity.

Repo popularitycaution

The repository has zero stars and forks and only two watchers. Popularity is supporting evidence rather than a verdict, but these counters provide little external validation.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
yard/data
Version ^2.0
—
—
roots/acorn
Version ^5.0
—
—
jgrossi/corcel
Version ^9.0
—
—
spatie/laravel-data
Version ^4.13
—
—
spatie/laravel-package-tools
Version ^1.16
—
—

Weekly Downloads

Info

Last Published
20 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform