This release appears healthy and suitable to depend on: it has a strong release history since 2021, 33 releases in the last 12 months, a recent push, stable non-prerelease versioning, an active non-archived repository, documented tests, a clear GPL-2.0-or-later license, and organization-owned project backing. The main risks are concentrated maintenance, with all 15 commits in the last 3 months from one contributor, limited repository popularity, no changelog, and no repository security policy or security-scanning tooling. These are meaningful resilience and transparency gaps, but they do not outweigh the evidence of active ongoing maintenance and regular releases.
82%
Total Score
83
100
89
90
One contributor made all 15 commits in the last 3 months, creating a genuine continuity risk. Organization ownership provides some potential handoff capacity, but no second active contributor is shown.
The repository has only 1 star, 0 forks, and 1 watcher. This does not establish abandonment for a small specialized package, but it provides little independent evidence of broad adoption or community support.
Composer build tooling is present, but no security-scanning tools are configured. The missing scanning is a security-hygiene gap, though it is not by itself evidence that the package is unsafe to depend on.
The repository has no SECURITY.md policy. The README supplies a security contact, which partly compensates for the missing formal policy, but coordinated vulnerability-reporting guidance remains limited.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/post-mutations Version ^19.2.4 | — | — |
pop-cms-schema/post-categories Version ^19.2.4 | — | — |
pop-cms-schema/category-mutations Version ^19.2.4 | — | — |
pop-cms-schema/custompost-category-mutations Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.