This is a healthy, actively maintained release with a substantial history: 161 releases over roughly 5 years, 33 releases in the last 12 months, a stable non-prerelease version, and a source repository that is current and not archived. The package is licensed, documented, tested in the repository, has a small runtime dependency footprint, and has no install-time lifecycle scripts or dangerous workflows. The main concerns are that recent repository work is concentrated entirely in one contributor, the repository has no security policy or security-scanning tooling, and the repository has negligible public popularity; organization ownership and the strong release cadence partially offset these concerns. It appears reasonable to depend on, subject to normal review of its concentrated maintainer base.
78%
Total Score
70
100
89
90
Only one registry account has publish access, which is a mild operational concentration risk; the organization-owned source repository and strong release activity provide some compensating project backing.
All 14 recent commits came from one contributor, creating a genuine continuity risk. Organization ownership provides some handoff potential, but no second active contributor is shown to offset the concentration.
There were no new or merged pull requests in the last month and no issue activity was recorded; this is a limited transparency signal, but it does not outweigh the recent commit and release cadence.
The repository has 0 stars and 0 forks with 1 watcher, so there is little external adoption evidence; popularity is supporting evidence only and is outweighed here by active releases and recent commits.
Composer is used as a build tool, but no security-scanning tooling is detected; the build tooling is appropriate while the security-automation gap warrants caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/queriedobject Version ^19.2.4 | — | — |
pop-cms-schema/schema-commons-wp Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.