The project is clearly identified, licensed, tested, and still has organizational backing. Its registry release cadence is inactive, recent commit activity is absent, and workflow references are not pinned, so maintenance and build-reproducibility concerns remain.
65%
Total Score
83
83
50
The package has 32 releases, but none in the last 12 months; its latest release was about 2 years and 4 months ago. This is a meaningful maintenance concern, although the repository remains active in other collected signals.
There were no commits from active maintainers in the last three months, weakening the recent-maintenance picture even though the repository was pushed recently.
Six stars and four forks indicate a small user base, but popularity is supporting evidence and does not outweigh the maintenance signals.
Composer is used for builds, but no security scanning tool is configured. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.12 | — | — |
grottopress/wordpress-suv Version ^1.0 | — | — |
grottopress/mobile-detector Version ^1.0 | — | — |
grottopress/wordpress-posts Version ^1.0 | — | — |
grottopress/wordpress-meta-box Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.