This is a healthy, actively maintained release with a strong release history, stable versioning, an unarchived and correctly matched source repository, explicit licensing, tests, and recent publication activity. The main concerns are that all 15 commits in the last 3 months came from one contributor, the repository has very low popularity, and it lacks a repository security policy and security-scanning tooling. These concerns reduce resilience and transparency somewhat, but the organization-owned project backing, 154 releases over more than five years, 33 releases in the last 12 months, and recent repository push substantially mitigate abandonment risk.
82%
Total Score
90
100
89
90
One contributor made all 15 commits in the last 3 months, giving the repository a top-contributor share of 100%. This creates a genuine continuity risk, although organization ownership provides some capacity for maintenance handoff.
The repository has only 2 stars, 0 forks, and 1 watcher. Low popularity is supporting caution about external validation, but it is not by itself evidence of abandonment for a small, actively released package.
Composer is used as a build tool, but no security-scanning tools are present. The missing security scanning lowers supply-chain transparency, while the build tooling itself is appropriate for this package.
The repository has no SECURITY.md or other detected security policy. The README provides an email contact for security issues, which is useful, but the absence of a formal policy remains a transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/users Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.