This is a healthy, actively maintained release with a strong five-year history, 154 releases, 33 releases in the last 12 months, stable versioning, a current non-archived repository, explicit licensing, tests, and a coherent package tree. The main risks are maintenance concentration in one active contributor, low repository popularity, and the absence of a security policy or security-scanning tooling; these are meaningful hygiene and bus-factor concerns but are partly offset by organization ownership, frequent recent releases, and ongoing repository activity. It appears reasonable to depend on, subject to the project’s small-contributor-base risk.
82%
Total Score
90
100
89
100
All 15 recent commits came from one contributor, creating a genuine bus-factor risk. Organization ownership provides some handoff capacity, but no second active contributor is shown to compensate fully.
The repository has only 2 stars, 0 forks, and 1 watcher. This limits external adoption evidence, but popularity is supporting evidence rather than a decisive health measure and is offset by the release and commit history.
Composer is used as a build tool, but no security-scanning tools are detected. The absence of scanning is a security-hygiene gap, though it does not by itself indicate abandonment or make the package unfit to use.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/posts Version ^19.2.4 | — | — |
pop-cms-schema/categories Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.