This is a healthy, actively maintained release with a five-year history, 150 releases, 32 releases in the last 12 months, a stable non-prerelease version, and a repository that is current, correctly associated with the package, and organization-backed. The main concerns are concentrated maintenance in one recent contributor, low repository adoption metrics, no security scanning or security policy, and no changelog; these are meaningful transparency and resilience gaps but are outweighed by the strong release cadence, active repository, licensing, tests, and absence of risky lifecycle scripts or dangerous workflows.
82%
Total Score
83
100
89
90
All 15 recent commits came from one contributor, creating meaningful continuity risk; organization ownership partially compensates because maintenance can potentially be handed off within the project.
The repository has only 2 stars, 0 forks, and 1 watcher, indicating limited public adoption; this is supporting caution rather than a decisive health problem because maintenance activity is strong.
Composer build tooling is present, but no security scanning tools were detected; the missing scanning coverage lowers assurance without demonstrating an unsafe release process.
The linked repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented despite the README providing an email contact.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-cms-schema/menus-wp Version ^19.2.4 | — | — |
pop-wp-schema/schema-commons Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.