A Docker-based development stack for Bedrock WordPress multisite, optimized for local development, source control, and CI/CD integration.
61%
Total Score
caution
Usable with caveats: release activity stopped nearly two years ago despite an unarchived, well-documented repository.
A post-install Composer script runs during installation. This is a supply-chain consideration, although the signal does not show that the script is unsafe.
Only one registry account has publishing access, creating a thin publishing base; the matching user-owned repository provides some compensating project context but not maintainer redundancy.
The package has had no registry release in nearly two years and no releases in the last 12 months, which raises maintenance and abandonment concerns.
There were no commits and no active maintainers in the last three months, a concrete sign that development has slowed or stopped.
The repository uses Composer for builds, but no security-scanning tools were detected, leaving a modest security-process gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
roots/bedrock Version ^1.24 | — | — |
oscarotero/env Version ^2.1 | — | — |
roots/wordpress Version 6.6.2 | — | — |
roots/wp-config Version 1.0.0 | — | — |
vlucas/phpdotenv Version ^5.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.