This is a healthy, actively maintained Composer package with a long release history, 154 releases since 2021, 33 releases in the last 12 months, and a recent stable release. The linked organization-owned repository is not archived, matches the package, and explicitly documents the package; licensing, README coverage, tests, build tooling, and dependency scope are also solid. The main concerns are that all 14 recent commits came from one contributor, there is no changelog or repository security policy, and repository popularity is very low, but these are mitigated by ongoing release and commit activity and organization backing. It appears reasonable to depend on, subject to normal review of its small contributor base and limited security-process transparency.
88%
Total Score
80
100
89
90
Only one registry publishing maintainer is listed, which is a limited publishing base. However, this is less concerning because the linked repository is owned by an organization and the package shows substantial ongoing release activity.
All 14 commits in the last 3 months came from one contributor, creating a concentrated operational dependency. Organization ownership provides some potential handoff capacity, but no second active contributor is observed.
The repository has only 2 stars, 0 forks, and 1 watcher, indicating limited public adoption or visibility. Popularity is supporting evidence rather than a decisive health measure, and active releases compensate for much of this concern.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning automation is a process gap, although it is not by itself evidence of poor package health.
The linked repository has no SECURITY.md or other detected security policy, reducing transparency about vulnerability reporting and response procedures.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/tags-wp Version ^19.2.4 | — | — |
pop-cms-schema/customposts-wp Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.