The package includes a clear README, matching source repository, MIT licensing, and a security policy. Two active contributors support the project, though its build and security tooling are limited.
67%
Total Score
88
50
88
100
The package declares 13 runtime dependencies, including WordPress, plugins, deployment components, and monitoring. This is a relatively broad dependency surface for a boilerplate, but it is coherent with the package's full-stack role.
The latest registry release was published in August 2018, with no releases in the last 12 months. Recent repository commits partly compensate, but the release itself is substantially stale.
There were no new or closed issues or pull requests in the last month, while seven issues remain open. This weakens evidence of responsive project management, although recent commits provide some compensation.
The repository reports no build tooling and no security scanning tools. For a deployment-oriented WordPress scaffold, the absence of security scanning is a genuine maintenance and transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sentry/sentry Version * | — | — |
vlucas/phpdotenv Version ^2.0.1 | — | — |
composer/installers Version ~1.0.12 | — | — |
johnpbloch/wordpress Version * | — | — |
wpackagist-plugin/nginx-cache Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.