The repository remains linked to the package and has a clear MIT license, README, and changelog. No security policy is present, and the workflow audit failed to fully analyze its files.
38%
Total Score
50
90
50
The latest release was published in March 2019, with no releases in the last 12 months despite the package being about 8 years old. This strongly increases abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and indicating no observable current maintenance.
The linked repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a package that configures a WordPress application.
The audit found no reported workflow issues, but one of the repository's one workflow files failed analysis, so this is incomplete evidence rather than a clean audit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
oscarotero/env Version ^1.1.0 | — | — |
roots/wordpress Version 5.1.1 | — | — |
roots/wp-config Version 1.0.0 | — | — |
vlucas/phpdotenv Version ^3.0.0 | — | — |
composer/installers Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.