This is a mature, actively released package with 162 releases over roughly 5 years, 33 releases in the last 12 months, a stable non-prerelease version, current repository activity, tests, a clear README, an explicit GPL-2.0-or-later license, and no install-time lifecycle scripts. The main concerns are that all 14 commits in the last 3 months came from one contributor, the repository has very low popularity, no security scanning or security policy was detected, and no changelog is present; these reduce resilience and transparency but do not outweigh the strong release and maintenance evidence. Overall, it appears reasonable to depend on, with normal single-maintainer and security-process caveats.
82%
Total Score
75
100
89
100
Only one registry publishing maintainer is listed, which is a potential publishing continuity concern. However, the repository is organization-owned and shows sustained recent releases, so this is not treated as a severe risk.
One contributor made all 14 commits in the last 3 months, creating a genuine continuity and bus-factor concern. Organization ownership provides some structural backing but does not show that another contributor is currently active.
The repository has only 2 stars, 1 fork, and 1 watcher. This indicates limited external adoption or visibility, but popularity is supporting evidence rather than a health verdict.
Composer build tooling is present, but no security scanning tool was detected. The missing scanning evidence is a security-process hygiene gap rather than evidence of maliciousness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-api/api-graphql Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.