The single maintainer and missing consumer documentation limit confidence in ongoing support. The package is licensed and has a coherent theme file layout, but the repository could not be found, so maintenance and provenance cannot be checked.
48%
Total Score
50
100
63
75
The release declares a proprietary license, so it is not clearly permissive for use as an open-source dependency even though a license is explicitly provided.
A post-create-project-cmd script runs during installation. This is plausible for a Composer project, but it adds installation behavior that consumers must understand and trust.
Only one registry publishing account is listed, leaving limited visible publishing redundancy and increasing continuity risk if that maintainer becomes inactive.
The package has had no releases in the last 12 months, and its latest release was about 14 months ago. That weakens confidence in continued maintenance for a WordPress theme.
Version 0.7 is not yet at a stable major release, which suggests the public interface and theme behavior may still change substantially.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^5.2 | — | — |
symfony/console Version ^6.2 | — | — |
symfony/filesystem Version ^5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.