This is a healthy, actively maintained release with a strong release history: 154 releases over roughly 5 years, 33 in the last 12 months, and a latest release on the assessment date. It is stable, not deprecated, clearly licensed, linked to a matching organization-owned repository, and has recent commit activity, tests, and a clean package tree. The main concerns are maintenance concentration in one contributor, the absence of a repository security policy, and limited repository popularity; these warrant some dependency risk awareness but do not outweigh the sustained release and commit activity. The package is reasonable to depend on, with contingency planning for single-maintainer continuity.
82%
Total Score
90
100
89
100
One contributor made all 14 commits in the last 3 months, producing a 100% top-contributor share. The organization-owned repository partly compensates for this concentration, but individual continuity remains a real concern.
The repository has only 2 stars, 0 forks, and 1 watcher. This limits popularity-based supporting evidence, but popularity is not decisive and the package has strong release and commit activity.
Composer is used as a build tool, but no security scanning tools are reported. The lack of scanning is a hygiene gap, not a severe risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/tags-wp Version ^19.2.4 | — | — |
pop-cms-schema/customposts-wp Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.