This is a healthy, actively maintained release with a long history, frequent recent releases, stable versioning, a non-deprecated registry status, explicit licensing, tests, and a matching repository with recent commits. The main reservations are that all recent repository commits come from one contributor, no security policy or security scanning tooling is present, and no changelog was found; however, organization ownership, active release cadence, repository tests, and clear package-to-repository linkage substantially reduce the abandonment and transparency concerns. It appears reasonable to depend on, subject to normal review of its small contributor base and security practices.
82%
Total Score
90
100
89
90
One contributor made all 15 commits in the last 3 months, creating a real concentration risk; organization ownership provides some ability to hand maintenance off but does not eliminate the observed single-contributor dependency.
The repository has only 3 stars, 1 fork, and 1 watcher, indicating limited external adoption evidence; this is supporting information rather than a decisive health problem for a focused package.
Composer build tooling is present, but no security scanning tools were detected; the build setup is appropriate while security-process transparency is limited.
No repository security policy was found, leaving vulnerability-reporting guidance less formal despite the README containing an email-based security contact.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/users Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.