This is a healthy, actively maintained Composer package with a strong release history: it is over five years old, has 154 releases, and published 33 releases in the last 12 months. The stable non-prerelease version, absence of registry deprecation, current repository push, organization-owned backing, matching repository identity, documented tests, and license all support dependable adoption. The main concerns are that all 17 recent commits came from one contributor, the repository has no security scanning or security policy, and repository popularity is low; these reduce resilience and transparency but do not outweigh the evidence of ongoing maintenance and frequent releases.
82%
Total Score
90
100
89
100
All 17 commits in the last 3 months came from one contributor, creating a genuine continuity risk; organization ownership provides some ability to hand maintenance off but does not eliminate the observed concentration.
The repository has only 2 stars, 0 forks, and 1 watcher. Low popularity is supporting caution rather than a verdict, since the package shows frequent releases and recent commits.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a transparency and defense-in-depth gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/schema-commons Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.