The road to full Packagist coverage

Plumb scores a growing set of PHP packages today. The destination is a mechanically verifiable score for every public package on Packagist.

Where we are today

Plumb tracks a curated, steadily expanding subset of the registry. Every scan is mechanically verifiable and its raw data is cached, so each new check can backfill against fetches we already hold — coverage deepens as it widens.

Coverage

Tracking 73,354 packages so far.

Where we're headed

The intent, and soon: scan and score every maintained public package on Packagist, so any dependency you pull already has a Plumb score waiting.

Coverage stops at packages that are still alive. A package a maintainer has marked abandoned on Packagist is not pulled into coverage — a package declared dead does not need a fresh score, and any package we already track that becomes abandoned scores 0 in every category.

What's next

Wider coverage is one thread of a longer plan. We're working toward hosting support beyond GitHub, more checks across all three categories, and continual refinement of the checks already in place.

Have a package host you'd like covered, a check you'd like to see, or feedback on a score? Reach out on X or email us at [email protected].

Learn more

The scoring page explains the categories, weights, and every check that goes into a score.