Licensing is clear, the repository matches the package, and Dependabot is configured. The single maintainer and inactive issue tracker provide little evidence of ongoing support.
55%
Total Score
25
80
50
The latest release was over 5 years ago, with no releases in the last 12 months; this is a substantial maintenance concern for a WordPress integration package.
The repository recorded no commits in the last 3 months, and its last push was over 4 years ago, indicating that active maintenance has largely stopped.
There were no new or closed issues or pull requests in the last month, while 3 issues and 3 pull requests remain open; this weakens evidence of support.
The repository has no security policy, leaving vulnerability-reporting expectations unclear; this is a transparency gap, though it is not decisive by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.5 | — | — |
league/oauth1-client Version ~1.7 | — | — |
league/oauth2-google Version ~3.0 | — | — |
league/oauth2-facebook Version ~2.0 | — | — |
league/oauth2-linkedin Version ~5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.