This is a healthy, mature release with a five-year history, 162 releases, 33 releases in the last 12 months, a recent publication, stable versioning, clear licensing, tests, a coherent 38-file source tree, and no install-time lifecycle scripts. The main concern is maintenance concentration: all 15 commits in the last three months came from one contributor, and the repository has no security policy or security-scanning tooling. The organization-owned repository and strong release cadence provide meaningful support, so these are cautions rather than evidence that the package is unfit to depend on.
82%
Total Score
75
100
89
90
Only one registry account has publish access, which is a modest publishing-resilience concern; however, this package is backed by an organization-owned repository and the registry access list does not measure actual maintenance activity.
One contributor made all 15 commits in the last three months, creating a real continuity risk; organization ownership provides some ability to hand off maintenance but no second active contributor is shown.
The repository has zero stars and forks and only one watcher, providing little independent adoption evidence; this is supporting evidence only and is outweighed by the package's sustained release activity.
Composer is used as a build tool, but no security-scanning tools are reported, leaving a security-transparency gap despite the package's otherwise active maintenance.
The linked repository has no security policy, which weakens vulnerability-reporting transparency; the README does provide an email route for security issues, partially compensating for the missing repository policy.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getpop/engine Version ^19.2.4 | — | — |
pop-cms-schema/schema-commons Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.