The package has a declared GPL-2.0-only license and no install-time scripts, but provides no tests or README. Its two-file artifact, single maintainer, and absent security tooling leave little evidence of maturity or ongoing care.
35%
Total Score
25
71
67
This package has made only one release, on March 16, 2018, and none in the last eight years. That long period without a new release is strong evidence of abandonment risk.
The repository recorded no commits and no active maintainers in the last three months, consistent with the unchanged release history. No provided signal shows current maintenance capacity.
Only one registry publisher is listed, which leaves a thin publishing base. The repository is user-owned rather than organization-backed, so no provided signal compensates for that concentration.
The package contains only composer.json and index.php, matching the repository. This may be a deliberately small implementation, but it provides little visible structure or supporting documentation for assessing maturity.
The artifact has no README, tests, or changelog, although release notes exist for this exact version and document that no documentation was provided. The missing consumer documentation and tests reduce transparency for a WordPress integration package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.