It has a clear MIT license, a matching repository, and a simple Composer dependency profile. Its small five-file tree and lack of security tooling limit transparency, while the project shows little evidence of ongoing stewardship.
43%
Total Score
0
100
64
50
This is the only release, published about 8 years ago, with no releases in the last 12 months. That strongly raises abandonment risk despite the package remaining available.
The repository has had no commits and no active maintainers in the last 3 months, consistent with the long release gap and weak evidence of current maintenance.
The package contains a focused five-file tree with the theme CSS and service provider, fitting a small theme package. Its minimal scope limits transparency but does not by itself indicate unsafe packaging.
The repository name matches the package, which supports ownership, but the README does not mention the package explicitly. The mismatch concern is therefore limited rather than decisive.
Composer is used for the build, but no security scanning tooling is present. This is a modest transparency gap, especially alongside the lack of recent maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.