Usable with caveats: the package is clearly backed by its organization, includes tests, documentation, and a security policy, but it has had only one release and no recorded commits in the last three months. Treat it as a low-churn dependency and verify that it still fits your WordPress and Elasticsearch versions.
62%
Total Score
67
81
100
This release is the package's only release, published about four years ago, with no releases in the last 12 months. That limited history and lack of ongoing release activity raise maintenance concerns.
No commits or active maintainers were recorded during the last three months. That is the clearest maintenance concern for a package whose only registry release is already several years old.
There is only one open issue and two open pull requests, but none were created or merged in the last month. This suggests limited recent project activity without proving abandonment.
Composer build tooling is present, but no security-scanning tool was detected. This is a transparency gap, partially offset by the repository's separate security policy.
The package remains at v0.1.0, indicating an early project stage even though the registry does not mark it as a prerelease. This limits evidence of long-term API stability.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.