This is a healthy, actively maintained release with a five-year history, 161 releases, 33 releases in the last 12 months, and a latest push matching the assessment date. It has a stable non-prerelease version, is not deprecated or archived, includes a clear GPL license, tests, a substantial source tree, and no install-time lifecycle scripts. The main concerns are concentrated recent contribution activity from one contributor, no repository security policy or security-scanning tooling, and no changelog despite the README referring to one; however, the organization-owned repository and strong release cadence materially reduce abandonment risk. Repository popularity is low, but that is supporting evidence rather than a decisive health concern.
82%
Total Score
80
100
83
90
Only one registry publishing account is listed, which is a modest publishing-resilience concern. The organization-owned repository provides compensating project backing, so this is not a severe risk.
A substantial README and tests are present in both the artifact context and repository, supporting usability and maintenance. The missing changelog is a minor hygiene gap, although the package documentation provides development, testing, and security-reporting guidance.
All 16 recent commits came from one contributor, creating concentration risk. Because the repository is owned by an organization, maintenance can potentially be handed off, which partly compensates for the low individual bus factor.
The repository has only 2 stars, 0 forks, and 1 watcher, indicating limited external adoption. This is weak supporting evidence but does not outweigh the active release and commit history.
Composer is used as a build tool, but no security-scanning tools are detected. The missing scanning coverage is a transparency and defense-in-depth gap rather than evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/queriedobject Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.