The README still says the project is in development and leaves setup unfinished, while install and update scripts run automatically. It has one maintainer, no license, and the repository could not be found, making long-term support and safe reuse difficult.
18%
Total Score
50
25
50
No declared license, license file, or detected license is present, so developers have no clear permission to use or redistribute this package.
The last release was in September 2016, with no releases in the last 12 months; this strongly indicates abandonment for a package still marked as in development.
The package runs post-install and post-update commands, adding avoidable installation and upgrade behavior to an already poorly maintained dependency.
Only one registry maintainer is listed, leaving little visible capacity or redundancy for ongoing maintenance.
A README is present, but it says the project is in development and leaves Getting Started as TODO; the absence of tests and a changelog is normal for a published artifact and is not treated as a gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
epoch2/http-codes Version ^1.0.0 | — | — |
composer/installers Version ^1.0 | — | — |
moxie-lean/wp-endpoint Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.