This is a healthy, mature release with a strong publication history: it has existed for over 5 years, has 154 releases including 33 in the last 12 months, and the latest release is stable and not deprecated. The package is licensed, includes a README and tests, has no install-time lifecycle scripts, and is backed by an active, non-archived organization-owned repository that matches the package. The main concerns are that all 14 recent commits came from one contributor, repository popularity is very low, and no security policy or security-scanning tooling was found; these reduce resilience and transparency but do not outweigh the sustained release and repository activity.
82%
Total Score
90
100
89
90
One contributor made all 14 commits in the last 3 months, creating a concentrated maintenance dependency; organization backing provides some handoff capacity but does not eliminate the bus-factor concern.
The repository has only 2 stars, 0 forks, and 1 watcher, which provides little external adoption evidence; low popularity is supporting caution rather than a health verdict.
Composer build tooling is present, but no security-scanning tools were detected, leaving a security-hygiene gap.
The repository has no security policy, leaving reporting and vulnerability-handling expectations less transparent for dependents.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/post-categories Version ^19.2.4 | — | — |
pop-cms-schema/custompost-categories-wp Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.