The package is clearly documented, licensed, and closely matched to its source repository. Maintenance appears paused, with no releases in 12 months and no commits in the last three months; the single-maintainer project also lacks a security policy.
58%
Total Score
50
94
83
Only one registry maintainer is listed. Because the project backing is an individual account rather than an organization, this leaves limited visible publishing redundancy.
The registry namespace and repository are owned by the same individual account, which supports ownership continuity but provides no organizational backing or visible maintainer redundancy.
The package has seven releases overall, but none in the last 12 months; its latest release was over a year ago. This indicates paused maintenance for a package that may still be usable, so it lowers confidence in ongoing support.
The repository had zero commits and zero active maintainers in the last three months. Combined with no releases in the last 12 months, this is evidence of a currently inactive project.
The repository has no published security policy. For a small WordPress plugin this is a transparency gap, although it does not by itself indicate that the release is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.