This is a healthy, actively maintained Composer package with a five-year history, 161 releases, 33 releases in the last 12 months, and a recent stable release. The linked repository is active, unarchived, correctly associated with the package, and backed by an organization, while the package is licensed and has a clear README, tests, and standard Composer tooling. The main concerns are complete concentration of recent commits in one contributor and the absence of repository security scanning and a security policy; these reduce resilience and transparency but are not enough to make the package unsuitable to depend on.
82%
Total Score
90
100
94
90
The artifact contains source files, Composer configuration, static-analysis configuration, a license, documentation, and tests. The only test file is named ModuleTestDisabled.php, which limits confidence in active test coverage but does not indicate an incomplete package.
One contributor made all 15 commits in the last 3 months, creating a genuine single-maintainer continuity risk. Organization ownership provides some potential handoff capacity, but no second active contributor is shown.
Composer build tooling is present, supporting reproducible project workflows, but no security-scanning tool was detected, leaving a security-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/user-roles-wp Version ^19.2.4 | — | — |
pop-cms-schema/customposts-wp Version ^19.2.4 | — | — |
pop-cms-schema/custompost-mutations Version ^19.2.4 | — | — |
pop-cms-schema/user-state-mutations-wp Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.