It includes a clear README, changelog, MIT license, and no install-time scripts. Repository activity stopped after the initial release, and it has no security policy or security scanning, limiting confidence in ongoing support.
58%
Total Score
50
86
83
All three releases were published within minutes on 17 February 2025, followed by about 19 months with no releases. This suggests the package may be a one-off port rather than an actively maintained dependency.
There were zero commits and zero active maintainers in the last three months, consistent with no meaningful repository activity since February 2025 and raising maintenance risk.
Composer and Phing build tooling are present, but no security scanning tools are configured. That is a modest transparency and maintenance gap rather than evidence of immediate unfitness.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This lowers transparency for a package used in WordPress projects.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.0 | — | — |
hassankhan/config Version ^3.0 | — | — |
composer/installers Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.