The package is clearly identified, MIT-licensed, stable, and has a matching repository with a usable README. Its tiny four-file project has no tests or security policy, and the repository has shown no release activity since August 2016; pinning this release carries substantial abandonment risk.
42%
Total Score
50
63
75
Only two releases were published, both in August 2016, with none in the last 12 months despite the package being over 10 years old. This is strong evidence of abandonment risk.
The package contains only four files, including its manifest, README, license, and plugin source. This is transparent and plausible for a tiny WordPress plugin, but leaves little evidence of development safeguards.
A README is present and a GitHub release exists for this version, but the package and repository have no tests or changelog. The release documentation is still adequate for this small plugin, while the lack of tests modestly limits confidence.
The registry namespace and repository owner match, and the owner is an individual account. This provides direct ownership alignment but no organization-level backing to compensate for the inactive project.
There are no open issues or pull requests and no activity in the last month. While this may reflect the plugin's small scope, it offers no evidence of ongoing maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.