This is a generally healthy and actively maintained release: it has a stable version, 154 releases over more than five years, 33 releases in the last 12 months, recent repository activity, a clear GPL license, tests, and no registry deprecation or install-time lifecycle scripts. The main concerns are that all recent commits come from one contributor, the linked repository neither matches the package name nor mentions the package in its README, and no repository security policy or security-scanning tooling was detected. These issues warrant review before adoption but do not outweigh the package's strong release cadence, current maintenance, and organization-owned repository context.
78%
Total Score
70
100
89
90
Only one registry account has publish access, which is a concentration concern, although the linked source repository is owned by an organization and the package has strong recent release activity.
One contributor made all 14 commits in the last 3 months, creating a genuine single-maintainer continuity risk; organization ownership provides some backing but no second active contributor is shown.
The repository recorded 14 commits in the last 3 months, demonstrating recent maintenance, but all activity came from one active maintainer.
The repository name does not match the package name and the README does not mention the package, so the linkage is less transparent and should be verified before depending on it, even though the package README identifies a related monorepo location.
Composer build tooling is present, but no security-scanning tooling was detected; the missing scanner is a modest supply-chain hygiene gap rather than evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/category-mutations-wp Version ^19.2.4 | — | — |
pop-cms-schema/custompost-mutations-wp Version ^19.2.4 | — | — |
pop-cms-schema/custompost-categories-wp Version ^19.2.4 | — | — |
pop-cms-schema/custompost-category-mutations Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.