This is a healthy, actively maintained release with a five-year history, 162 releases, 33 releases in the last 12 months, and a latest release published very recently. The package is not deprecated or archived, has a stable major version, a clear GPL-2.0-or-later license, tests, substantial source structure, and no install-time lifecycle scripts. Its main risks are maintenance concentration in one active contributor, the absence of repository security scanning and a security policy, and very low repository popularity; these are meaningful transparency and resilience gaps but are partly offset by organization ownership, current commit activity, and frequent releases.
86%
Total Score
83
100
89
88
One contributor made all 16 commits in the last 3 months, creating a genuine continuity and bus-factor risk; this is softened because the repository is owned by an organization that can potentially provide maintenance handoff.
The repository has only 1 star, 0 forks, and 1 watcher, so there is little external adoption evidence; this lowers confidence in community resilience but is not decisive for a small, actively released package.
Composer is used as a build tool, but no security-scanning tools are detected, leaving a security-process transparency gap.
No repository security policy was found, so the preferred process for reporting and handling vulnerabilities is not formally documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getpop/root Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.