The package has clear documentation, tests, a stable release, and organization backing. Its short history, single active contributor, missing security policy, and unpinned workflow actions leave meaningful maintenance and build-reproducibility concerns.
66%
Total Score
67
100
88
83
The package is only 47 days old with five releases all published on the same day, so there is not yet enough history to demonstrate sustained maintenance or release stability.
All three recent commits came from one contributor, creating a concentrated maintenance risk. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Three commits in the last three months show some recent activity, but the low volume limits evidence of an established maintenance cadence.
Composer build tooling is present, but no security scanning tools are reported. This is a modest transparency and maintenance gap rather than evidence that the release is unsafe.
The repository has no security policy, leaving the vulnerability-reporting and response process undocumented for a library used in WordPress projects.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.