There is no security policy or security-scanning tooling, which leaves maintenance practices difficult to verify. The package is documented and licensed, but that does not offset its lack of ongoing support.
15%
Total Score
0
63
50
Packagist marks the entire package as abandoned, with no replacement specified. Package-level deprecation is a severe warning against taking a new dependency.
The latest release was about 8 years ago, with no releases in the last 12 months. Although the project has a long history and 57 releases, this release is far beyond a normal maintenance window.
The repository recorded zero commits and zero active maintainers in the last 3 months. Combined with the old last push, this indicates ongoing maintenance has effectively stopped.
Composer build tooling is present, but no security-scanning tools were detected. This is a maintenance and transparency gap for a package that manages a WordPress application stack.
The repository is not archived, which avoids the strongest abandonment signal. However, its last push was about 7 years ago, so the unarchived status provides little practical reassurance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
oscarotero/env Version ^1.1.0 | — | — |
vlucas/phpdotenv Version ^2.0.1 | — | — |
composer/installers Version ^1.4 | — | — |
johnpbloch/wordpress Version 4.9.5 | — | — |
roots/wp-password-bcrypt Version 1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.