This is a healthy, actively maintained release with a strong release history: 162 releases over roughly 5.6 years, 33 releases in the last 12 months, and the latest release published very recently. The package is stable, not deprecated, licensed, backed by an organization-owned repository, and has matching source documentation, tests, and a coherent 67-file implementation tree. The main concerns are concentrated recent activity in one contributor, minimal repository popularity, and the absence of repository security scanning and a formal security policy; these warrant review for organizational continuity but do not outweigh the strong maintenance and release evidence.
82%
Total Score
80
100
89
100
One contributor made 100% of the 16 recent commits, creating a real continuity and bus-factor risk. Organization ownership partially mitigates the risk because maintenance can potentially be handed off, but no second active contributor is shown.
The repository recorded 16 commits in the last 3 months, showing active development, but all were made by one active maintainer.
The repository has only 1 star and no forks, indicating limited external adoption or visibility. Popularity is supporting evidence rather than a verdict, so this is a modest concern.
Composer is used as a build tool, but no security scanning tools are configured. The build setup is appropriate, while the missing scanning is a security-process gap rather than evidence of package ill health by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/posts Version ^19.2.4 | — | — |
pop-cms-schema/custompost-mutations Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.