This release shows strong ongoing maintenance evidence: it has existed for over five years, has 162 releases including 33 in the last 12 months, was released very recently, is not prerelease, and its linked repository received 14 commits in the last three months. It is licensed, includes a README and tests, uses Composer without install-time lifecycle scripts, and is backed by an organization-owned repository. However, the package is explicitly marked abandoned on Packagist with a replacement package, which is a major adoption risk even though development remains active, and the linked repository neither matches the package name nor mentions it in its README, creating uncertainty about package-to-source alignment. Commit activity is also concentrated entirely in one contributor, while the repository has no security policy or security scanning. Dependents should prefer the stated replacement unless compatibility requirements justify accepting the transition risk.
42%
Total Score
80
100
72
100
Packagist marks the package as abandoned and names getpop/custom-posts-wp as its replacement. This is a major dependency-safety and continuity concern despite the package still receiving recent releases.
All 14 recent commits came from one contributor, creating concentration risk. Organization backing provides some mitigation, but no second active contributor is shown.
There were no new issues or pull requests in the last month, and no pull requests were merged; this provides little evidence of community interaction, though the separate commit signal confirms ongoing maintainer activity.
The repository name does not match the package name and its README does not mention the package, leaving uncertainty about whether the linked repository directly corresponds to this release. A monorepo relationship may explain the mismatch, but the provided evidence does not establish that.
The repository has 2 stars, 0 forks, and 1 watcher, indicating limited adoption evidence. Popularity is supporting evidence rather than a verdict, so this is not treated as a major health defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/customposts Version ^19.2.4 | — | — |
pop-cms-schema/queriedobject-wp Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.