This is a healthy, actively maintained release with a long history, frequent recent releases, stable versioning, current repository activity, clear licensing, and a direct repository match backed by an organization. The main concerns are a single active contributor, very low repository popularity, no security scanning or security policy, and no changelog; these reduce resilience and transparency but do not outweigh the strong release and maintenance evidence. It appears reasonable to depend on, with ordinary precautions around maintainer concentration and independent security review.
82%
Total Score
80
100
89
90
Only one registry account has publish access, which is a concentration concern. However, the linked repository is owned by the PoPCMSSchema organization and the package has strong recent release activity, so this is a resilience caution rather than evidence of abandonment.
One contributor made all 14 commits in the last 3 months, giving the repository a 100% top-contributor share. Organizational ownership provides some handoff capacity, but no second active contributor is evidenced, so resilience is reduced.
The repository has only 2 stars, 0 forks, and 1 watcher, indicating limited external adoption or visibility. Popularity is supporting evidence rather than a verdict, so this is a minor concern given the strong maintenance signals.
Composer is used as a build tool, but no security-scanning tool is detected. The build tooling is appropriate for the ecosystem, while the missing scanning capability is a transparency and assurance gap.
The repository has no security policy file, although the README provides an email address for reporting security issues. The documented contact partly compensates for the missing formal policy, but security-process transparency remains limited.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/post-categories Version ^19.2.4 | — | — |
pop-cms-schema/custompost-categories-wp Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.