Frequent releases and a current source repository show ongoing work, but all recent commits come from one contributor and the repository has no security policy. The package should be replaced rather than newly adopted.
22%
Total Score
88
100
81
88
The package is deprecated at package scope through Packagist's abandoned mechanism, with pop-schema/user-state named as the replacement. This is a severe adoption risk even though other signals show recent maintenance.
One contributor made all 17 commits in the last 3 months. Organization ownership provides some handoff capacity, but the observed contributor base remains concentrated.
Composer is used as the build tool, but no security scanning tool was detected. The missing scanning is a hygiene gap rather than evidence of abandonment.
The linked repository has no security policy. For a package handling user login and state, this reduces transparency around reporting and response procedures.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/users Version ^19.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.