The README, release notes, and matching repository make setup and provenance reasonably clear. Treat it as a legacy starting point rather than an actively maintained dependency.
45%
Total Score
50
75
83
The package has only one release, published about 6 years and 10 months ago, with no releases in the last 12 months. The repository was pushed more recently, but the registry release history still indicates a largely unmaintained published artifact.
No license is declared, and neither the package nor the linked repository contains a license file. That leaves the legal terms for reuse unclear.
The package and repository are owned by the same individual account, with no organization backing shown. That is consistent with a small personal template but leaves a limited visible continuity base.
There are 17 open pull requests but no new or merged pull requests in the last month. That unresolved backlog is a modest sign of limited project follow-through.
Composer build tooling is present, but no security scanning tools were detected. For a small template this is a hygiene gap rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
roots/wordpress Version >=5.3 | — | — |
composer/installers Version ^1.7 | — | — |
rarst/fragment-cache Version ^1.3 | — | — |
rarst/update-blocker Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.