The road to full Packagist coverage
Plumb scores a growing set of PHP packages today. The destination is a mechanically verifiable score for every public package on Packagist.
Where we are today
Plumb tracks a curated, steadily expanding subset of the registry. Every scan is mechanically verifiable and its raw data is cached, so each new check can backfill against fetches we already hold — coverage deepens as it widens.
Tracking 73,354 packages so far.
Where we're headed
The intent, and soon: scan and score every maintained public package on Packagist, so any dependency you pull already has a Plumb score waiting.
Coverage stops at packages that are still alive. A package a maintainer has marked abandoned on Packagist is not pulled into coverage — a package declared dead does not need a fresh score, and any package we already track that becomes abandoned scores 0 in every category.
What's next
Wider coverage is one thread of a longer plan. We're working toward hosting support beyond GitHub, more checks across all three categories, and continual refinement of the checks already in place.
Have a package host you'd like covered, a check you'd like to see, or feedback on a score? Reach out on X or email us at [email protected].
Learn more
The scoring page explains the categories, weights, and every check that goes into a score.