This is a mature, actively maintained, stable package: it has 162 releases over roughly 5 years, 33 releases in the last 12 months, a current stable version, no registry deprecation, recent repository activity, tests, a complete small package tree, explicit licensing, and no install-time lifecycle scripts. The main concerns are that all 14 recent commits came from one contributor and the repository has no security policy or security-scanning tooling; very low repository popularity is supporting caution but is not decisive for a focused component. Overall, it appears reasonable to depend on, with normal review and monitoring appropriate for its concentrated maintenance model.
82%
Total Score
83
100
89
90
All 14 commits in the last 3 months came from one contributor, creating a genuine continuity risk; organization ownership provides some capacity for handoff but does not remove the observed concentration.
The repository has only 2 stars, 0 forks, and 1 watcher, indicating limited external adoption or review; this is supporting caution but is not by itself evidence that a small, actively maintained component is unsafe to depend on.
Composer build tooling is present, but no security-scanning tools were detected. The missing security automation is a transparency and assurance gap, though it is not evidence of abandonment.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented; the README's security contact provides partial practical coverage but not a formal policy.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-api/api Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.