This is a healthy, mature release with more than five years of history, 163 releases, 33 releases in the last 12 months, a stable non-prerelease version, active recent commits, tests in both the artifact and repository, clear licensing, and no install-time lifecycle scripts. The main concerns are that all 14 commits in the last three months came from one contributor, the repository has no security policy or security-scanning tooling, and repository popularity is very low; organization backing and the package's matching repository provide some mitigation, but these remain meaningful transparency and continuity gaps.
82%
Total Score
70
100
89
90
Only one registry account has publish access, which is a continuity concern, although the repository is backed by an organization and recent release activity is strong.
One contributor made all 14 commits in the last three months, creating a genuine continuity risk. Organization ownership provides some ability to hand off maintenance, but no second active contributor is shown.
There were no new or merged pull requests and no issue activity in the last month; this is a limited collaboration signal, though the open pull request count is zero and commit activity remains present.
The repository has only 1 star, 0 forks, and 1 watcher. Popularity is supporting evidence rather than a verdict, but this provides little external adoption signal.
Composer build tooling is present, but no security-scanning tools were detected, leaving a security-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-api/api Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.