The package is small, clearly licensed, documented, and has no install-time scripts. Its one-person ownership and lack of security scanning leave less maintenance and review capacity than ideal.
55%
Total Score
50
100
88
75
The registry lists one maintainer, while the linked repository is owned by the same individual. This provides clear ownership but leaves limited apparent maintainer redundancy.
The latest release was published in July 2023, with no releases in the following three years and only three releases overall. This indicates substantially slowed maintenance for a security-related WordPress plugin.
The repository recorded no commits and no active maintainers in the past three months, consistent with the long release gap. The repository is not archived, but there is no recent development evidence.
The linked repository has no security policy, which is a transparency gap for a package intended to address a security concern. Its small scope partly limits the impact, but there is no documented reporting process.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.