This is a mature, actively maintained Composer package with 162 releases since January 2021, 33 releases in the last 12 months, stable versioning, a non-deprecated registry entry, a matching source repository, and 14 commits in the last three months. Licensing, README guidance, tests, and a minimal runtime dependency set further support adoption. The main concerns are that all recent commits come from one contributor, the repository has very limited popularity, and no security policy or security-scanning tooling was detected; these are meaningful transparency and continuity gaps, but the organization-owned project backing and strong release activity reduce the abandonment risk. No install-time lifecycle scripts or dangerous workflows were found.
80%
Total Score
70
100
89
90
Only one registry account has publish access, which is a continuity concern in isolation. The repository is owned by an organization and the package has substantial recent release activity, partly compensating for the narrow registry publishing base.
One contributor made all 14 commits in the last three months, creating a meaningful continuity risk. Organization ownership provides some ability to hand off maintenance, but no second active contributor is evidenced here.
There were no new issues or pull requests in the last month, and no pull requests were open. This provides little evidence of external review or collaboration, though it does not establish abandonment given the recent commit and release activity.
The repository has only 1 star, 1 fork, and 1 watcher, indicating limited external adoption or visibility. Popularity is supporting evidence rather than a decisive health measure, so this is a caution rather than a severe risk.
Composer is used as a build tool, but no security-scanning tooling was detected. The missing scanner lowers supply-chain transparency, although it is not evidence of maliciousness or abandonment by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/pages Version ^19.2.4 | — | — |
pop-cms-schema/customposts-wp Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.