This is a mature, actively maintained and clearly licensed package with a strong release cadence: it has existed since 2021, has 162 releases, 33 releases in the last 12 months, and the assessed version is stable and current. The linked repository is active, unarchived, correctly associated with the package, and backed by an organization, with tests and Composer tooling present. The main concerns are that all 14 recent commits came from one contributor, the repository has very low visible popularity, and no security policy or security-scanning tooling was detected; these reduce resilience and transparency but do not outweigh the sustained release activity and organizational backing.
82%
Total Score
60
100
89
100
Only one registry account has publish access, which is a mild publishing-resilience concern. However, the linked repository is organization-owned and shows sustained recent release activity, partly compensating for the narrow registry maintainer list.
One contributor made 100% of the 14 commits in the last 3 months, creating a concentrated bus factor. Organization ownership provides some potential handoff capacity, so this is caution rather than danger.
The repository recorded 14 commits in the last 3 months, all from one active maintainer. The commit volume supports current maintenance, while the lack of contributor diversity remains a resilience concern.
There were no new or closed issues or pull requests in the last month, and the open issue count is unknown. This provides little evidence about issue responsiveness, though the absence of issue activity alone is not evidence of abandonment.
The repository has only 1 star, 0 forks, and 1 watcher. This is limited supporting evidence of adoption, but popularity is not decisive and is outweighed here by the active release and commit history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/post-tags Version ^19.2.4 | — | — |
pop-cms-schema/custompost-tags-wp Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.