The package is small and clearly documented, with a narrow dependency set. Its install-time Composer hooks add operational complexity, and the pre-1.0 version offers limited maturity evidence.
38%
Total Score
100
70
75
The latest release was published in June 2017, with no releases in the last 12 months. That long period without updates is strong evidence of abandonment risk for a package intended for ongoing WordPress use.
The package runs post-install and post-update Composer scripts. These hooks add installation-time behavior that should be understood before adoption, although their presence alone is not evidence of unsafe behavior.
Version 0.1.3 is not a prerelease, but the package remains below 1.0, which provides limited evidence of a mature, stable public API.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.