A release note documents a concrete fix, and the organization-backed repository is not archived. The repository has no security scanning or policy, so operational transparency is limited.
65%
Total Score
67
100
88
75
The manifest labels the package proprietary, with no license file detected in the package or repository. It is therefore licensed, but its terms may restrict adoption and provide less clarity for open-source consumers.
There were no commits and no active maintainers in the last three months. The recent release history partly offsets this, but the current development pause lowers confidence in ongoing maintenance.
The repository has no open issues and two open pull requests, but no issues or pull requests were merged in the last month, providing limited evidence of active project handling.
Composer is used for builds, but no security scanning tooling was detected. This is a transparency and maintenance-hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy. That leaves vulnerability reporting and response expectations unclear for a package intended to run in WordPress installations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1.4 | — | — |
psr/container Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.