This is a generally healthy and actively maintained release: it has recent, frequent releases, substantial recent commit activity, an unarchived repository, matching repository documentation, tests and changelog coverage, and sound workflow-risk results. The main concerns are that it remains below a stable major version, is published by one registry maintainer, has a highly concentrated commit share, uses install and update lifecycle scripts, lacks a repository security policy, and does not declare top-level workflow permissions; these warrant review but do not outweigh the strong evidence of ongoing maintenance and project transparency.
82%
Total Score
70
100
94
70
The package defines post-install-cmd and post-update-cmd scripts, which add install-time execution and therefore require dependency consumers to review their behavior.
Only one account, Brian Henry, has registry publish access, creating a publishing continuity risk. This is partly supported by the repository's active recent work but remains a single-publisher concern.
The repository is owned by an individual user rather than an organization, so there is no organizational maintenance handoff implied by the ownership context. This makes the concentrated maintainer activity more consequential.
Two contributors were active, but the leading contributor made about 91% of recent commits. This concentration creates continuity risk, although the second contributor and recent activity provide partial mitigation.
The repository has no security policy. This reduces vulnerability-reporting transparency, though it is a documentation gap rather than evidence of unsafe code or abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
monolog/monolog Version ^3 | — | — |
wptrt/admin-notices Version ^1.0 | — | — |
brianhenryie/bh-wc-logger Version >=0.1.0 | — | — |
brianhenryie/bh-wp-cli-logger Version >=1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.