Custom Widgets for WordPress.
28%
Total Score
unhealthy
Risky: no release or commit activity since May 2017, and the package says it is not ready for production.
The latest release was in May 2017, with no releases in the last 12 months despite the package being over nine years old. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history and indicating no current maintenance.
The manifest declares MIT while the artifact license file is detected as GPL-3.0. Although a license file exists, this mismatch creates a meaningful adoption and compliance concern.
The package has a README, but it explicitly says the project is in development and not ready for production. Missing tests and a changelog are normal for published artifacts and are not counted against it.
The linked repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This compounds the risk for an old package with no recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-di/php-di Version ^5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.