This is a mature and actively maintained release: it has been published for over 5 years, has 162 releases including 33 in the last 12 months, releases roughly every 4 days, and currently has 15 commits in the last 3 months. The package is licensed, non-deprecated, reproducibly structured as a Composer package with tests and a substantial source tree, and its repository is active, unarchived, organization-owned, and correctly associated with the package. The main concerns are that all recent commits come from one contributor, there is no changelog despite the README referring to one, no repository security policy or security-scanning tooling was observed, and the repository has negligible public popularity; these reduce resilience and transparency but do not outweigh the strong release and maintenance history.
78%
Total Score
80
100
83
90
The artifact and repository include a substantial README and tests, but neither includes a changelog even though the README directs users to one. The missing changelog is a modest transparency gap.
All 15 recent commits came from one contributor, with a 100% top-contributor share and only one active contributor. Organization ownership provides some handoff context, but no second active contributor is shown, so resilience remains a genuine concern.
There were no new or closed issues or pull requests in the last month, and no pull requests were open. This provides little evidence of community interaction, though the active commit and release history reduces abandonment concern.
The repository has 0 stars and 0 forks, with 1 watcher. This is weak supporting evidence for community adoption, but popularity is not decisive and the package's release and commit activity compensate for it.
Composer build tooling is present, but no security-scanning tools were detected. Build support is adequate while security-process transparency is limited.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/user-state Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.