A clear README, exact-version release notes, and matching MIT licensing help consumers understand and use it. The repository also has a security policy and a coherent 53-file package tree, though no automated security-scanning tool is reported.
67%
Total Score
67
88
100
The package and repository are owned by the same individual account rather than an organization. This is consistent ownership, but it provides no organizational handoff capacity to offset contributor concentration.
The package has only 3 releases since May 2023, with a median interval of about 503 days and just 1 release in the last 12 months. The February 2026 release shows the project is not abandoned, but its cadence is slow.
All 4 recent commits came from one contributor, giving the project a fragile maintenance base despite the repository remaining active. A maintainer becoming unavailable could slow fixes substantially.
Composer is used for builds, but no security-scanning tools are reported. That is a maintenance and assurance gap for a WordPress framework, though it is not evidence of a security defect by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.