The license text is narrower than the manifest declaration, and the project has no security policy or scanning tool. Recent commits and organization ownership provide some maintenance support.
66%
Total Score
100
100
83
83
The artifact contains a GPL-2.0 license file, but the manifest declares GPL-2.0-or-later; this mismatch should be clarified before redistribution or adoption.
This is the package's first observed release, published less than a day ago, so there is no release history to demonstrate sustained maintenance or stability.
Composer build tooling is present, but no security-scanning tools were detected, leaving a notable verification gap for a WordPress plugin.
The repository has no security policy, so vulnerability reporting and disclosure expectations are not documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.