The README is useful and the package has a simple PHP-only dependency profile. Releases stopped about 5 years and 9 months ago, with no commits or active maintainers in the last 3 months. Its tiny repository and lack of security scanning add transparency concerns.
43%
Total Score
0
100
78
67
The package has had no release in about 5 years and 9 months, despite only 8 releases overall. This is strong evidence of abandonment for a package tied to changing WordPress and ACF integrations.
There were 0 commits and 0 active maintainers in the last 3 months. Combined with the last release being about 5 years and 9 months ago, this indicates substantial abandonment risk.
The artifact and repository each contain five files, including the manifest, lock file, README, and main PHP file. The very small tree limits evidence of project maturity but is not inherently unhealthy for this focused plugin.
The repository has 1 star, 0 forks, and 1 watcher, providing little community evidence or external maintenance support. Low popularity is supporting evidence rather than a verdict by itself.
Composer is used as a build tool, which fits the package ecosystem, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.