The package is clearly documented and tested, with a small runtime dependency surface. Its short release history, single active contributor, missing security policy, and license mismatch leave meaningful maintenance and transparency concerns.
58%
Total Score
75
100
70
50
The manifest declares GPL-2.0-or-later, while the only detected license file is MIT for vendored Select2 assets; the mismatch should be clarified before redistribution.
The package has only two releases, both published within the same day, so there is not yet enough history to demonstrate sustained maintenance or release stability.
One contributor made all 37 commits in the last three months, leaving maintenance highly dependent on a single person; the repository owner is an individual rather than an organization.
The repository has no security policy, leaving no documented process for reporting and handling vulnerabilities in a WordPress-facing library.
Version v0.1.1 is not a prerelease, but it remains below 1.0, indicating an early API and project maturity stage.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.