This is a mature, actively maintained and regularly released package: it has existed since January 2021, has 162 releases including 33 in the last 12 months, is on a stable non-prerelease version, is not deprecated, and was pushed very recently. The package is licensed, has source-aligned files and tests, uses Composer without install-time lifecycle scripts, and is backed by an organization-owned repository. The main concerns are that all 15 recent commits came from one contributor, the repository has no security policy or security-scanning tooling, and the package has little public popularity; these reduce resilience and transparency but do not outweigh the strong release and maintenance evidence.
82%
Total Score
70
100
83
90
Only one registry account has publish access, which is a resilience concern, although registry access does not measure actual maintenance and the source repository is organization-owned.
A substantial README and tests are present, and the README documents development, testing, issue reporting, and security contact practices. A changelog is absent from both the artifact and repository, which is a minor transparency gap.
One contributor made all 15 commits in the last 3 months, creating a high concentration risk. The organization-owned repository provides some institutional backing, but no second active contributor is evidenced.
There were no new or closed issues or pull requests in the last month and no open pull requests. This does not demonstrate abandonment because recent commit activity and release activity are strong, but it provides little evidence of community interaction.
The repository has only 1 star, 0 forks, and 1 watcher, indicating limited external adoption or visibility. This is supporting evidence only and is outweighed by the strong release and commit activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/taxonomies Version ^19.2.4 | — | — |
pop-cms-schema/customposts-wp Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.