This is a generally usable and actively published stable package with a clear MIT license, a substantial and coherent source tree, a matching repository, changelog, release automation, and no deprecation or archive signal. However, adoption carries moderate maintenance and transparency risk: the package has only eight releases over nearly seven years, no tests in either the artifact or repository, very low repository adoption, unresolved pull requests with no recent issue or PR progress, a relatively large runtime dependency surface, and a workflow without explicit top-level token permissions. The package appears suitable for use with normal dependency and release monitoring, but it is not as strongly validated or broadly maintained as a mature foundational dependency.
72%
Total Score
67
50
83
70
Fifteen runtime dependencies create a meaningful transitive maintenance and supply-chain surface for a project scaffold, though the declared dependencies are consistent with its broad WordPress stack functionality.
The package uses a post-root-package-install script, which adds installation complexity and execution surface, although this is consistent with a Composer project scaffold rather than inherently unhealthy.
A substantial README and changelog are present, and the repository uses GitHub Releases; the absence of tests is a genuine validation gap for this application scaffold.
The repository is owned by a personal user account rather than an organization, so there is limited evidence of institutional backing or a broad continuity plan.
The package has existed for about 6 years and 9 months, with releases in the last 12 months, but only eight releases overall and a median interval of about 118 days indicate a relatively modest release cadence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
oscarotero/env Version ^2.1 | — | — |
jazzman/wp-mail Version ^2.0 | — | — |
roots/wordpress Version ^6.9 | — | — |
roots/wp-config Version ^1.0 | — | — |
vlucas/phpdotenv Version ^5.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.