The MIT license, matching repository, and stable version make its purpose and ownership clear. Its two install-time scripts deserve extra review before adoption.
38%
Total Score
25
75
50
The package is about 7 years old but has had no release in roughly 7 years, with zero releases in the last 12 months. This is strong evidence of abandonment risk despite eight historical releases.
The repository recorded zero commits and zero active maintainers during the last 3 months, consistent with the long release gap and indicating no current maintenance activity.
The package runs post-create-project-cmd and post-root-package-install scripts during Composer operations. These scripts are expected for an installer package but increase the impact of depending on an unmaintained release.
Only one registry publishing maintainer is listed. For this user-owned project that is a thin maintainer base, increasing continuity risk when there is no recent activity.
The repository has 7 stars, 2 forks, and 1 watcher. Low adoption is supporting evidence of limited project maturity, but it is not decisive for a small utility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
johnpbloch/wordpress Version >=5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.