This is a mature, actively maintained and transparently packaged release: it has existed for over 5 years, has 154 releases including 33 in the last 12 months, is stable, non-deprecated, licensed, and backed by an active organization-owned repository. The main concerns are concentrated maintenance, with all 17 commits in the last 3 months from one contributor, and limited repository security hygiene because no security scanning tools or security policy were detected. These concerns are moderated by the organization backing, recent commit activity, tests, a matching repository, and the absence of install-time scripts or dangerous workflows.
82%
Total Score
90
100
94
88
All 17 recent commits came from one contributor, creating a genuine continuity risk; the organization-owned repository provides some compensation but does not eliminate the concentration.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-hygiene gap.
The repository has no security policy, reducing transparency about vulnerability reporting and response procedures.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/schema-commons Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.