The package is licensed, documented, tested, and not deprecated. Install-time scripts and limited security tooling leave some transparency gaps, but the project has recent activity and a maintained source repository.
72%
Total Score
50
100
94
63
Post-install and post-update Composer scripts add execution during dependency operations, increasing review and reproducibility considerations even though no malicious behavior is established here.
The repository is owned by an individual rather than an organization, so the one-person activity and bus factor are not offset by visible organizational backing.
One contributor made all 6 commits in the last 3 months, creating a concentrated maintenance dependency with no observed handoff capacity.
Six commits were made in the last 3 months, but all came from one active maintainer, so activity is current while continuity depends on one person.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest project-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-stubs/wordpress-stubs Version ^5.3 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.