This release appears healthy and suitable to depend on: it has a long release history, frequent recent releases, a stable non-prerelease version, an active non-archived repository, matching package documentation, and an organization-backed project. The main risks are concentration of recent development in one contributor, lack of repository security scanning and a formal security policy, and the absence of a changelog despite the README referring to one. These are meaningful transparency and resilience gaps, but they are outweighed by strong ongoing release and commit activity and the absence of deprecation or install-time lifecycle scripts.
82%
Total Score
90
100
83
90
The artifact includes a README and tests, and the README documents installation, development, testing, issue reporting, and security contact details. A changelog is absent both from the package and repository, which leaves a modest transparency gap.
All 14 recent commits came from one contributor, creating a low bus factor and a resilience risk. Organization ownership provides some handoff potential but does not eliminate the observed concentration.
The repository has no stars or forks and only one watcher, so there is little popularity-based external validation. This is supporting evidence only and does not outweigh the active release and commit history for a small component.
Composer is used as a build tool, but no security-scanning tools are configured, leaving a security-hygiene gap.
The repository has no formal security policy. The README does provide a security email address, which partially compensates for the missing SECURITY.md-style policy but leaves reporting guidance less formal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pop-wp-schema/meta Version ^19.2.4 | — | — |
pop-cms-schema/taxonomymeta-wp Version ^19.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.