This release is actively maintained and appears mature: it has 161 releases over roughly 5.6 years, 33 releases in the last 12 months, a stable non-prerelease version, recent repository pushes, and 16 commits in the last 3 months. The package is licensed, includes a README and tests, has a modest dependency footprint, and does not run install-time scripts. However, it is explicitly marked abandoned on Packagist with getpop/custom-posts as the replacement, which is a major adoption concern despite current activity. Maintenance is also concentrated in one contributor, the repository has very low popularity, lacks a security policy, and the repository does not clearly reference the exact package name, so adopting this package should generally be avoided in favor of the stated replacement unless compatibility requirements make migration impractical.
42%
Total Score
88
100
72
90
Packagist marks the package as abandoned and names getpop/custom-posts as its replacement. This is a severe dependency-health concern even though the assessed release is recent.
One contributor made all 16 commits in the last 3 months, creating a high bus-factor risk. Organization ownership partly mitigates handoff risk but does not remove the current concentration concern.
The repository name does not match the package name and its README does not mention the exact package name. Although the artifact README identifies the broader monorepo context, the collected result still leaves package-to-repository identity less transparent.
The repository has only 2 stars, 0 forks, and 1 watcher. Popularity is supporting evidence rather than a verdict, but these very low counts provide little external validation.
Composer is used as a build tool, but no security-scanning tools are reported. The absence of scanning lowers transparency and assurance, though it is not by itself evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/queriedobject Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.