This release appears suitable for dependency use: it has a long release history, frequent recent releases, a stable non-prerelease version, an active and non-archived source repository, clear licensing, tests, and no install-time lifecycle scripts. The main concerns are that all recent repository commits come from one contributor, the project has very low popularity, and no repository security policy or automated security scanning was detected; however, organization ownership and strong ongoing release activity partly mitigate the maintainer-concentration concern. The missing changelog is a minor transparency gap because the package README directs users to a changelog that was not found.
82%
Total Score
90
100
89
90
One contributor made 100% of the 16 commits in the last 3 months, creating a meaningful continuity risk. Organization ownership provides some ability to hand off maintenance, but no second active contributor is shown.
The repository has only 1 star, 0 forks, and 1 watcher. This limits external validation and community support, although popularity is supporting evidence rather than a verdict.
Composer is used as a build tool, but no security-scanning tools were detected. The missing scanning is a security-hygiene gap, though it does not establish maliciousness or make the package unfit on its own.
The repository has no SECURITY.md or equivalent security policy, reducing transparency for vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/customposts Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.