This release has strong evidence of active development and reasonable package hygiene: it is a stable version from a package with 162 releases, 33 releases in the last 12 months, a recent repository push, and 14 commits in the last three months. However, the registry explicitly marks the package as abandoned and identifies pop-schema/media-wp as the replacement, which is a major adoption and continuity risk even though the linked organization-owned repository remains active. The single-contributor activity and absence of a security policy add caution, so developers should prefer the replacement package unless compatibility requirements make this package necessary.
42%
Total Score
75
100
78
90
The package is explicitly marked abandoned on Packagist, with pop-schema/media-wp named as its replacement. This is a severe continuity and adoption risk despite the linked repository remaining active.
Only one registry publisher is listed, which would normally be a concentration concern. The organization-owned repository and active source history provide some compensating project backing, though registry continuity still depends on a single publisher.
All 14 recent commits came from one contributor, creating a meaningful bus-factor risk. Organizational ownership partly compensates because maintenance can potentially be handed off, but no second active contributor is evidenced.
The repository has only 1 star and no forks, indicating limited visible adoption. Popularity is supporting evidence rather than a verdict, so this lowers confidence in ecosystem maturity but is not independently severe.
Composer is used as a build tool, but no security-scanning tools are detected. The missing scanning coverage is a security-hygiene gap, though it does not establish an unsafe release by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/media Version ^19.2.4 | — | — |
pop-cms-schema/customposts-wp Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.