The project offers little evidence of ongoing maintenance or consumer documentation. Its organization ownership and clean release setup provide some accountability, but the long period without activity makes future fixes uncertain.
38%
Total Score
50
100
67
75
The package has only one release, published about 9 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk.
The repository has had no commits and no active maintainers in the last 3 months, consistent with its last push about 9 years ago. This materially lowers confidence in future maintenance.
The package contains only composer.json and wp-custom-post-image.php, indicating a very small distribution. That may suit a simple WordPress plugin, but it leaves little visible project documentation or validation structure.
The artifact has no README, tests, or changelog, though the exact release has GitHub release notes saying “deploy plugin.” Missing tests and changelog are normal in published artifacts, but the absent README reduces consumer transparency.
The latest version is v0.2 rather than a stable major release, which suggests limited maturity. Its non-prerelease status provides only a small counterweight.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.