This release appears to be a generally healthy dependency: it has a roughly five-and-a-half-year release history, 162 releases including 33 in the last 12 months, a current stable version, no registry deprecation, an active non-archived organization-owned repository, and clear package/repository alignment. The main concerns are concentrated maintenance by one contributor, limited repository popularity, and the absence of a repository security policy or security-scanning tooling. These reduce resilience and transparency but do not outweigh the strong evidence of ongoing maintenance and consistent publishing.
78%
Total Score
80
100
89
100
Only one registry account has publish access, which is a resilience concern, although this is partly compensated by the linked repository being owned by an organization and by evidence of frequent recent releases.
One contributor made all 14 commits in the last three months, creating a meaningful bus-factor and continuity risk. Organization ownership provides some potential handoff capacity but does not show a second active contributor.
The repository has only 2 stars and no forks, so independent adoption evidence is limited; popularity is supporting evidence rather than a decisive health requirement.
Composer build tooling is present, but no security-scanning tools are configured. The missing scanning is a transparency and defense-in-depth gap, not evidence of maliciousness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/users-wp Version ^19.2.4 | — | — |
pop-cms-schema/user-state Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.