This is a healthy, actively maintained release with a strong release history: the package is over five years old, has 162 releases, 33 releases in the last 12 months, and was updated very recently. It is not deprecated or archived, has a stable major version, an explicit GPL-2.0-or-later license with a license file, a small runtime dependency surface, repository tests, and no install-time lifecycle scripts. The main concerns are concentrated maintenance activity from one contributor, no repository security policy or security scanning, and no changelog in the collected package or repository metadata; however, organization ownership, direct package/repository alignment, recent commits, and documented testing and release practices substantially mitigate these concerns.
84%
Total Score
83
100
88
75
A substantial README and tests are present in both the artifact and repository. A changelog is not present in the collected metadata, but the documentation directs users to a changelog, so this is a limited transparency gap.
All 15 recent commits came from one contributor, creating a genuine continuity risk. Organization ownership provides some maintenance handoff potential, but no second active contributor is shown.
Composer build tooling is present, but no security-scanning tools are reported, leaving a security-process transparency gap.
No repository security policy was found, which weakens the documented process for reporting and handling vulnerabilities even though the README provides a security contact.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/schema-commons Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.