This release has strong evidence of active and transparent development: it has 162 releases over roughly 5 years, 33 releases in the last 12 months, a stable version, a matching repository with tests and a clear README, recent commits, an organizational owner, a declared GPL license, and no install-time lifecycle scripts. However, Packagist explicitly marks the package as abandoned and identifies pop-schema/taxonomymeta-wp as its replacement; that deprecation is the dominant concern for taking a new dependency, even though recent release and commit activity suggests the project is being migrated rather than simply abandoned. The repository also has a single active contributor, no security policy, and no security scanning tooling, so adoption should generally favor the replacement package.
38%
Total Score
80
100
83
90
Packagist marks this package as abandoned and provides pop-schema/taxonomymeta-wp as the replacement. This is a severe dependency-sustainability warning despite the package's recent release activity.
One contributor made all 16 commits in the last 3 months, creating meaningful continuity risk. Organization ownership provides some mitigation, but it does not establish that another maintainer is currently active.
There were no new or closed issues and no pull requests in the last month. This provides little evidence of community activity, but the recent commit and release history shows ongoing maintainer work.
Composer build tooling is present, but no security scanning tools are configured. The build setup is appropriate, while the absent scanning coverage is a modest transparency and security-hygiene gap.
The linked repository has no security policy, leaving vulnerability-reporting expectations and handling procedures undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/metaquery-wp Version ^19.2.4 | — | — |
pop-cms-schema/taxonomymeta Version ^19.2.4 | — | — |
pop-cms-schema/taxonomies-wp Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.