This is a mature, actively maintained release with a long history since 2014, 231 releases, 25 releases in the last 12 months, and a stable non-prerelease version. The linked repository is active, unarchived, well-popularized, has substantial recent commit and pull-request activity, tests, changelog, and reproducible-looking Composer-based project structure. The main concerns are that registry publishing is controlled by one maintainer, recent commits are concentrated in one primary contributor, the repository has no declared security policy or security scanning, workflow token permissions are not explicitly top-level constrained, and the repository does not match the package name or mention it in its README, creating some package-to-source transparency risk. Overall, it appears suitable to depend on, but the repository linkage and security-governance gaps warrant verification for security-sensitive deployments.
82%
Total Score
70
100
89
80
Only one registry account, Andy Fragen, has publish access. This is a modest publishing-resilience concern, though the repository's observed activity provides compensating evidence of ongoing maintenance.
The repository is owned by an individual GitHub user rather than an organization, so there is no organizational succession context to offset the single registry maintainer and concentrated commit activity.
The primary contributor made about 69% of recent commits, creating concentration risk; however, a second contributor supplied about 29% and four contributors were active, so this is a caution rather than a severe abandonment signal.
The repository name does not match the package name and its README does not mention the package. Because this signal specifically indicates that the linked repository may not belong to the package, it is a meaningful source-to-package transparency concern.
Composer build tooling is present, but no security-scanning tools were detected. The build setup is positive, while the missing security automation leaves a genuine governance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
afragen/singleton Version ^1.0 | — | — |
freemius/wordpress-sdk Version ^2.12 | — | — |
afragen/wp-readme-parser Version ^1.0 | — | — |
afragen/wp-dismiss-notice Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.