This is a healthy, actively maintained package with a release history dating to 2021, 162 releases, 33 releases in the last 12 months, and a recent stable release. It is not deprecated or archived, has a matching and package-specific source repository, includes licensing, tests, Composer-based build tooling, and no install-time lifecycle scripts. The main concerns are that all 15 recent commits came from one contributor, the repository has minimal popularity, and no security policy or security-scanning tooling was detected; these reduce resilience and transparency but do not outweigh the strong ongoing release and commit activity.
82%
Total Score
83
100
89
90
One contributor made all 15 commits in the last 3 months, creating a genuine continuity risk. The organization-owned repository provides some potential handoff capacity, so this is caution rather than a severe health failure.
The repository has 1 star, 0 forks, and 1 watcher, indicating very limited external adoption or review. Popularity is supporting evidence rather than a verdict, so this modestly lowers confidence and health but is not independently disqualifying.
Composer build tooling is used, supporting reproducible project conventions, but no security-scanning tools were detected. The missing security automation is a transparency and defense-in-depth gap.
The linked repository has no security policy. This leaves vulnerability reporting and coordinated disclosure less explicit, creating a hygiene concern for a dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/customposts Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.