Healthy and suitable to use, with a concentrated maintenance base to watch. It has a long release history, recent releases, an active unarchived repository, tests, and straightforward build tooling, but all recent commits came from one contributor and the repository lacks a security policy.
78%
Total Score
75
100
100
75
All seven recent commits came from one contributor. Organization backing provides some handoff capacity, but no second contributor was active in the measured period, so this remains a meaningful concentration risk.
Seven commits were made in the last three months, showing current work, but only one maintainer was active during that period, limiting maintenance capacity.
No security policy was found in the repository, leaving vulnerability-reporting and response expectations unclear for a security-relevant WordPress plugin.
All four workflows omit top-level token permissions declarations. No workflow requests top-level write access, but explicit least-privilege settings would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.