This release appears healthy and reasonably safe to depend on from a maintenance and supply-chain transparency perspective. It has been actively released, with 6 releases in the last 12 months and a latest release on 2026-09-08, while the linked repository is not archived and shows 126 commits from two active contributors in the last 3 months. The repository contains tests, changelog documentation, CI workflows, Composer tooling, and Dependabot scanning, and the package is clearly linked to its matching source repository. Remaining concerns are the 0.x version line, install-time Composer scripts, the absence of a security policy, and workflows that do not declare top-level token permissions; these warrant review but do not outweigh the strong recent maintenance and repository evidence.
86%
Total Score
88
100
89
63
The package runs post-install-cmd and post-update-cmd scripts, creating additional install-time execution surface that should be reviewed before adoption.
The repository is owned by an individual user rather than an organization, so maintenance continuity depends primarily on the observed individual and contributor activity.
The repository has only 3 stars, 0 forks, and 1 watcher, so external adoption evidence is limited; this is a supporting concern rather than a health verdict for a small package.
The repository has no SECURITY.md or other detected security policy, reducing transparency around vulnerability reporting and response.
All 8 workflows lack top-level token permissions declarations, although none declares top-level write permissions and three constrain permissions at job level; explicit least-privilege declarations would improve CI hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1 || ^2 || ^3 | — | — |
wptrt/admin-notices Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.