This is a generally healthy and actively maintained release: it has 145 releases over roughly 3.7 years, 33 releases in the last 12 months, a stable non-prerelease version, current repository activity, an organization-owned non-archived repository, clear licensing, and a package-specific repository with tests. The main risks are maintenance concentration in one contributor, very low repository popularity, no security scanning or security policy, and no changelog in the collected package tree; these warrant caution but are outweighed by the strong release cadence and recent activity. The package appears reasonable to depend on, with normal supply-chain diligence recommended.
78%
Total Score
90
100
89
100
All 14 recent commits came from one contributor, creating a genuine bus-factor risk. The organization-owned repository partly compensates because maintenance can potentially be handed off within the organization.
The repository has zero stars and forks and only one watcher. This limits external validation and visibility, although popularity is supporting evidence and does not outweigh the demonstrated release and commit activity.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning reduces security-process transparency, though it is not evidence that the package is malicious.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-wp-schema/meta Version ^19.2.4 | — | — |
pop-wp-schema/customposts Version ^19.2.4 | — | — |
pop-cms-schema/custompostmeta-wp Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.