The repository has no security policy or automated security scanning. Its nine runtime dependencies increase upkeep demands, while the stable MIT-licensed release remains clearly packaged.
38%
Total Score
0
50
79
50
The package has had no release in more than six years: its latest release was June 28, 2020, with none in the last 12 months. That strongly indicates abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving little evidence of current maintenance.
The package declares nine runtime dependencies, including WordPress and Symfony components, creating meaningful maintenance exposure for a project with no recent activity.
An install-time post-root-package-install script runs during installation, adding execution behavior that consumers should understand when adopting an otherwise dormant package.
Composer is used for builds, but no security scanning tools are present. This is a modest hygiene gap rather than a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/dotenv Version ^5.1 | — | — |
roots/wp-config Version ^1.0 | — | — |
composer/installers Version ^1.9 | — | — |
htmlburger/wpemerge Version ^0.16.0 | — | — |
johnpbloch/wordpress Version ^5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.