This release shows strong ongoing activity and reasonable package hygiene: it has a stable version, 162 releases since 2021, 33 releases in the last 12 months, recent repository activity, a matching source repository, a license, tests, and no install-time lifecycle scripts. However, Packagist explicitly marks the package as abandoned and identifies pop-schema/pages-wp as its replacement; that is a decisive adoption concern even though the repository remains active. The single-contributor activity and absence of security scanning or a security policy add operational risk, so new projects should depend on the replacement package rather than this abandoned name.
38%
Total Score
83
100
81
88
Packagist marks the package as abandoned and provides pop-schema/pages-wp as the replacement. This is a severe dependency-maintenance concern despite the package's recent releases and active repository.
All 14 recent commits came from one contributor, giving a 100% top-contributor share. Although organization ownership provides some handoff context, the observed short-term maintenance base remains concentrated.
Composer build tooling is present, but no security scanning tools are reported. The build setup is appropriate, while the missing security automation is a modest transparency and assurance gap.
No repository security policy was found. This weakens the project's documented vulnerability-reporting process, even though the README provides an email-based security contact.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/pages Version ^19.2.4 | — | — |
pop-cms-schema/customposts-wp Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.