This is a healthy, actively maintained release with a long history, frequent recent releases, stable versioning, explicit licensing, matching source repository, and recent commit activity. The repository is organization-owned and not archived, and the package has a small, understandable dependency profile with no install-time lifecycle scripts. The main concerns are that all recent commits come from one contributor, there is no repository security policy or security-scanning tooling, and the repository has minimal public popularity and issue activity; these reduce resilience and transparency but do not outweigh the strong release and maintenance evidence.
82%
Total Score
80
100
89
90
Only one registry account has publish access. This is a modest operational concentration, but it is less concerning because the source project is organization-owned and actual repository activity is available.
All 16 commits in the last 3 months were made by one contributor, creating a real continuity risk. Organization ownership provides some capacity for handoff, but no second active contributor is shown.
The repository has 0 stars and 0 forks, with 1 watcher. This is weak supporting evidence, but popularity is not decisive and the package has strong release and commit activity.
Composer is used as a build tool, but no security-scanning tools are detected. The absence of scanning lowers supply-chain hygiene, while the build tooling itself is appropriate for the package ecosystem.
The repository has no SECURITY.md or other detected security policy, leaving vulnerability-reporting expectations less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/settings Version ^19.2.4 | — | — |
pop-cms-schema/schema-commons-wp Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.