The project has a small footprint, no security policy, and install-time scripts that deserve extra review. It is licensed, documented, tested, and not archived, but its maintenance record is too old for a dependable current integration.
38%
Total Score
0
75
50
The latest release was over six years ago, with no releases in the last 12 months; this is strong evidence of abandonment risk despite seven total releases.
The repository recorded zero commits and zero active maintainers in the last three months, confirming that maintenance has not resumed recently.
The package runs post-autoload-dump, post-install-cmd, and post-update-cmd scripts; these increase install-time behavior and warrant review, especially in an old dependency.
The repository has zero stars and forks and only one watcher, offering little evidence of an active user or contributor community.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a package that integrates with WooCommerce.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
automattic/woocommerce Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.