The stable version, MIT license, matching repository, and setup documentation make the package easy to inspect and install. Its dated WordPress/PHP-era structure and limited project activity reduce confidence that current issues will be addressed.
38%
Total Score
50
78
83
The latest release was published on January 20, 2016, and there were no releases in the following 12 months of the observed history; this is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers over the last three months of observation, consistent with the package's long release gap.
There were no new or closed issues or pull requests in the observed month, offering no evidence of current maintenance or community response.
The repository has zero stars and forks and only five watchers. Popularity is not required for a healthy package, but these low figures provide little supporting evidence when activity is also absent.
Composer is used for builds, which supports reproducible project setup, but no security-scanning tooling is present; this is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^2.0.1 | — | — |
composer/installers Version ~1.0.12 | — | — |
johnpbloch/wordpress Version 4.4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.