Risky to adopt for a new project: the package has had no release or repository activity since December 2017 and only two releases. It is not deprecated or archived, and the repository matches the package with a valid MIT declaration, but its long inactivity makes future fixes and compatibility uncertain.
48%
Total Score
50
63
88
The latest release was in December 2017, with zero releases in the last 12 months and only two releases overall. This long period without updates is a substantial abandonment and compatibility concern.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release inactivity. No newer activity is provided to offset that concern.
The repository has zero stars and forks and only one watcher, providing little evidence of community adoption or outside review. Popularity is supporting evidence rather than decisive on its own, so this is a caution rather than a severe risk.
Composer is used as a build tool, showing basic project tooling, although no security scanning tools are configured. For this small static theme, the missing scanning is a hygiene limitation rather than decisive evidence of unfitness.
The linked repository is not archived, which is a positive sign, but its last push was still in December 2017. The unarchived status does not compensate for the observed lack of recent maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.