Usable with caveats: the repository is active, the package is licensed, and its build and test structure is clear. It is only 42 days old, all recent commits come from one maintainer, and the repository lacks a security policy.
68%
Total Score
63
100
88
80
Only one registry account can publish releases. This is a modest continuity concern, although the linked repository shows the same person actively maintaining the project.
The repository is owned by an individual rather than an organization, so the single-maintainer and single-contributor concentration is not offset by visible organizational backing.
The package is young at 42 days but has 48 releases and a release as recently as the assessment date. The very frequent releases suggest active publishing, though they provide limited evidence of long-term stability.
All 12 recent commits were made by one contributor, so maintenance depends entirely on that person and has a meaningful continuity risk.
The repository uses Composer and contains build tooling, but no security-scanning tools were detected. For a generated stub package this is a hygiene gap rather than evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-stubs/wordpress-stubs Version ^5.3 || ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.