Security documentation and automated scanning are absent, which leaves maintenance and disclosure practices less visible. The GPL license, substantial README, stable version, and organization-backed repository provide useful reassurance.
56%
Total Score
75
100
88
83
The latest release was about 13 months ago, with no releases in the last 12 months. Ten releases over roughly 22 months show prior activity, but the recent pause lowers confidence in continued maintenance.
The repository recorded no commits and no active maintainers in the last three months, consistent with the roughly 13-month gap since the latest release. The repository is not archived, which partially offsets abandonment concern but does not restore current activity.
Composer build tooling is present, but no security scanning tools were detected. This is a modest supply-chain and maintenance hygiene gap rather than evidence that the release is unsafe.
The repository has no published security policy, reducing transparency about vulnerability reporting and response for a plugin that synchronizes user data between sites.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version >=1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.