This is a healthy, actively maintained release with a strong release history: it has existed for over five years, has 162 releases, and published 33 releases in the last 12 months. The package is stable, licensed, non-deprecated, directly backed by an organization-owned repository, and its latest repository push closely matches the release date. Composer build tooling, repository tests, package identity matching, and the absence of install-time scripts provide useful transparency and reduce operational risk. The main concerns are a single active contributor, no security scanning or security policy, no changelog in either artifact or repository, and minimal repository popularity; these are meaningful hygiene and continuity limitations but are partly offset by the organization's backing and sustained release activity.
82%
Total Score
83
100
83
80
The artifact and repository have matching, non-truncated trees with source, configuration, licensing, documentation, and tests, indicating a coherent package layout. The only test file is named ModuleTestDisabled.php, so the apparent test presence offers less assurance than an active test suite would.
A substantial README and tests are present, and the README documents development, testing, contribution, and security-reporting paths. However, neither the artifact nor repository has a changelog; the README points to a changelog that is not present in the collected evidence, creating a modest transparency gap.
All 15 commits in the last 3 months came from one contributor, creating continuity risk. The organization-owned repository provides some capacity for handoff, but no second active contributor is evidenced.
The repository has only 1 star, 0 forks, and 1 watcher, indicating limited visible adoption. Popularity is supporting evidence rather than a decisive health measure, so this is a minor concern only.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a supply-chain hygiene gap, though it is not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/taxonomies Version ^19.2.4 | — | — |
pop-cms-schema/customposts-wp Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.