This release shows strong ongoing engineering activity and reasonable package hygiene: it has 162 releases over roughly 5 years, 33 releases in the last 12 months, a stable version line, an unarchived organization-owned repository, tests in the repository, and no install-time lifecycle scripts. However, Packagist explicitly marks version 19.2.4 as abandoned and points users to pop-schema/pages, which is a decisive adoption risk even though the repository was recently updated. The single-contributor activity and absence of a security policy add further caution. Developers should prefer the replacement package and migrate rather than take a new dependency on this abandoned package.
22%
Total Score
75
100
78
90
Packagist marks the package as abandoned and names pop-schema/pages as its replacement. This is a severe adoption and maintenance risk that outweighs the otherwise healthy release activity.
Only one registry account has publish access. That is a limited publishing base, but the organization-owned repository and active release history partly compensate for the registry-side concentration.
All 16 recent commits came from one contributor, giving a 100% top-contributor share and creating a real continuity risk. Organizational ownership provides some handoff potential but no second active contributor is evidenced.
The repository has 1 star, 0 forks, and 1 watcher, indicating a very small public user and contributor footprint. Popularity is only supporting evidence, but these counts provide little external resilience.
Composer is used as a build tool, but no security-scanning tools are reported. The missing scanning tooling is a hygiene gap, although it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/customposts Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.