This is a mature, actively maintained Composer package with 162 releases since 2021, 33 releases in the last 12 months, a stable current version, recent repository activity, clear licensing, matching source repository, tests, and no deprecation or install-time lifecycle scripts. The main risks are that all 16 recent commits came from one contributor, the repository has no security scanning or security policy, and the package has no changelog despite referring to one; organization backing and strong release activity partly mitigate the maintainer-concentration concern. Overall, it appears suitable to depend on, with routine supply-chain and continuity safeguards advisable.
82%
Total Score
80
100
94
90
Only one registry account has publish access, which is a continuity concern, although the linked repository is organization-owned and the package has strong recent release activity.
One contributor made all 16 commits in the last three months, creating a genuine continuity and review risk; organization ownership provides some mitigation but does not demonstrate a second active maintainer.
Composer build tooling is present, but no security-scanning tools are reported, leaving a supply-chain hygiene gap.
The linked repository has no SECURITY.md or other detected security policy, reducing transparency around vulnerability reporting.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/usermeta Version ^19.2.4 | — | — |
pop-cms-schema/users-wp Version ^19.2.4 | — | — |
pop-cms-schema/metaquery-wp Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.