This is a generally healthy and actively maintained release: it has a long release history, frequent recent releases, stable versioning, an active non-archived repository, clear licensing, tests, and no install-time lifecycle scripts. The main risks are operational rather than critical: all recent repository commits come from one contributor, the repository has no security scanning or security policy, and neither the artifact nor repository reports a changelog despite the README referring to one. Organization ownership provides some continuity, but adoption should still account for the concentrated maintainer base and limited repository popularity.
78%
Total Score
70
100
83
100
Only one registry account has publish access, which is a concentration risk. However, the linked repository is owned by the PoPCMSSchema organization, providing some project-level backing.
The artifact includes a substantial README and tests are present both in the package and repository. The absence of a changelog is a transparency gap because the README points users to one, and no repository changelog or release evidence compensates for it.
One contributor made all 16 commits in the last 3 months, creating a genuine single-person continuity risk. Organization ownership partially mitigates this, but no second active contributor is shown.
There were no new or merged pull requests and no new or closed issues in the last month; this is limited collaboration evidence, although it does not indicate unresolved issue accumulation because the open issue count is unknown.
The repository has only 1 star, 0 forks, and 1 watcher, indicating limited external adoption and review. Low popularity is supporting caution rather than a decisive health failure because release and commit activity are strong.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/custompostmedia Version ^19.2.4 | — | — |
pop-cms-schema/media-mutations Version ^19.2.4 | — | — |
pop-cms-schema/custompost-mutations Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.