Tests, release notes, a clear license, and organization backing provide useful maintenance context. More than two years without a release or recent commits, no security policy, and unpinned workflow actions increase maintenance and build-transparency risk.
58%
Total Score
50
100
88
67
There were no commits and no active maintainers in the last three months. Combined with no registry releases in over two years, this is strong evidence of slowed maintenance.
The package has 35 releases since 2021, but none in the last 12 months and its latest release was over two years ago. This indicates a substantial maintenance slowdown despite the established release history.
There are 20 open issues and two open pull requests, but no new or closed issues or merged pull requests in the last month. The unresolved queue adds a modest maintenance concern alongside the inactive release history.
Composer is used as a build tool, supporting reproducible project structure, but no security scanning tools were detected. The missing scanning layer is a modest transparency gap.
The repository has no security policy file, leaving reporting and response expectations undocumented for a security-sensitive SEO plugin.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 | — | — |
cmb2/cmb2 Version ^2.6 | — | — |
composer/installers Version ~1.0 | — | — |
a5hleyrich/wp-background-processing Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.