This is a healthy, actively maintained Composer package with more than five years of history, 162 releases, 33 releases in the last 12 months, a stable non-prerelease version, and a release pushed very recently. Its source repository is active, correctly associated with the package, organization-owned, licensed, and includes tests and build tooling. The main concerns are that recent commit activity is concentrated entirely in one contributor, the artifact has no changelog, and the repository lacks a security policy and security-scanning tools; these reduce resilience and transparency but do not outweigh the strong release and maintenance evidence.
84%
Total Score
90
100
94
88
All 16 recent commits were made by one contributor, creating a low individual bus factor. Organization backing partly compensates because maintenance can potentially be handed off, but contributor concentration remains a caution.
Composer is used as the build tool, but no security-scanning tools were detected. The missing scanning is a hygiene gap rather than a direct health verdict, since other evidence shows frequent releases and recent commits.
The repository has no security policy, leaving the preferred vulnerability-reporting process less explicit. The package README does provide a security contact, which partially compensates for the repository-level gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/metaquery-wp Version ^19.2.4 | — | — |
pop-cms-schema/taxonomymeta Version ^19.2.4 | — | — |
pop-cms-schema/taxonomies-wp Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.