Its narrow scope, MIT license, and matching repository make the package easy to inspect and integrate. The single maintainer and lack of security scanning leave less maintenance depth than mature dependencies.
58%
Total Score
75
100
83
75
The latest release was published in January 2024, with no releases in the following two years and eight months. This is meaningful staleness for a dependency, although the package has 26 releases and a long history.
There were no commits and no active maintainers in the last three months. Combined with the old latest release, this supports a caution about current maintenance.
The repository has one star and two forks, indicating limited external adoption and review. Popularity is only supporting evidence, so this modestly reduces confidence rather than determining the verdict.
Composer is used for the build, which fits the package ecosystem, but no security scanning tools were detected. The missing scanning is a hygiene limitation rather than a severe dependency risk.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations unspecified. This is a transparency gap, though it is less serious for this small, inactive package than archival or deprecation would be.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dashifen/repository Version ^4 | — | — |
dashifen/wp-debugging Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.