This release shows strong ongoing maintenance and maturity signals: it has 162 releases over approximately 5 years, 33 releases in the last 12 months, a stable version, recent repository activity, tests, a clear license, and organization-backed source ownership. However, Packagist marks the package as abandoned and provides a replacement package, which is a major adoption concern even though the repository remains active. Maintenance is also concentrated entirely in one contributor, and the repository has no security scanning or security policy. Developers should prefer the stated replacement package unless compatibility requirements specifically require this abandoned package.
42%
Total Score
83
100
81
83
Packagist marks the package as abandoned and identifies pop-schema/usermeta-wp as its replacement. This is a severe dependency-lifecycle concern despite the repository's continued activity.
One contributor made all 16 commits in the last 3 months, creating a significant continuity and handoff risk. Organization backing provides some mitigation, but no second active contributor is shown.
Composer build tooling is present, but no security scanning tools are configured. The build setup is appropriate, while the missing security automation is a hygiene gap.
The repository has no security policy. The README provides an email reporting route, but the repository-level absence still reduces security-process transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/usermeta Version ^19.2.4 | — | — |
pop-cms-schema/users-wp Version ^19.2.4 | — | — |
pop-cms-schema/metaquery-wp Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.