This release has strong evidence of ongoing project activity and reasonable package hygiene: it has a long release history, frequent recent releases, a stable version, an unarchived organization-owned repository with a recent push, tests, a license file, and no install-time lifecycle scripts. However, Packagist explicitly marks the package as abandoned and provides getpop/componentrouting as its replacement, which is a severe dependency risk despite the active replacement project. The linked repository also does not match the package name or mention it in its README, adding transparency uncertainty, while all recent commits come from one contributor and no security scanning or security policy is present. Developers should prefer the replacement package rather than depend on this release.
24%
Total Score
83
75
75
Packagist marks the package as abandoned and identifies getpop/componentrouting as the replacement. This is a severe adoption risk even though related source activity remains active.
All 14 recent commits came from one contributor, giving the repository a very low recent contributor diversity. Organization ownership provides some handoff capacity, but the observed concentration remains a maintenance concern.
The repository name does not match getpop/modulerouting and its README does not mention that package. Although the README describes component routing and points to a monorepo location, the mismatch still reduces package-to-repository transparency.
Composer is used as a build tool, but no security scanning tools are detected. Build tooling is appropriate, while the missing security automation is a modest transparency and assurance gap.
The linked repository has no security policy. The README provides a security contact, which partially compensates for the missing formal policy, but the repository-level gap remains.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getpop/root Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.