This release shows strong ongoing maintenance and reasonable package hygiene: it has 161 releases over roughly 5 years, 32 releases in the last 12 months, a stable version, tests, a license file, a small dependency surface, and recent repository activity. However, the package is explicitly marked abandoned on Packagist with a replacement package, which is a serious adoption concern despite the linked organization-owned repository being active and correctly associated with the package. Developers should prefer the stated replacement and treat this release as unsuitable for a new dependency unless compatibility constraints require it.
42%
Total Score
83
100
78
100
Packagist marks the package as abandoned and identifies pop-schema/metaquery-wp as its replacement. This is a severe maintainability and adoption risk even though other signals show the source repository remains active.
All 14 recent commits came from one contributor, creating a genuine concentration risk. The organization-owned repository provides some maintenance backing, but no second active contributor is shown.
The repository has 0 stars and 0 forks and only 1 watcher. Popularity is supporting evidence rather than a verdict, but these values provide little external adoption or resilience evidence.
Composer is used as a build tool, which is appropriate for this PHP package, but no security scanning tools are reported. This is a transparency and defense-in-depth gap rather than evidence of unsafe behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/schema-commons-wp Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.