It has a clear README, a valid license, and only one runtime dependency. Organizational backing and a linked repository help, but limited security tooling leaves less assurance for a WordPress integration.
58%
Total Score
75
100
79
50
The latest release was published in April 2022, and there have been no releases in the last four years. The short five-release history suggests limited ongoing maintenance.
The repository recorded no commits and no active maintainers in the last three months, consistent with a project that has been inactive since its last release.
The repository has 1 star and 0 forks, providing little community evidence or backup capacity. Popularity is only supporting evidence, so this is a modest concern rather than a decisive risk.
Composer is used for the build, which supports reproducible project structure, but no security scanning tools are configured. That reduces automated assurance without indicating a direct defect.
The repository has no security policy, so there is no documented channel or process for handling vulnerabilities. This is a transparency gap, although the package is small and has a simple dependency profile.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
geniusts/hijri-dates Version 1.1.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.