LoSys - WP/Timber Starter Project
38%
Total Score
unhealthy
Risky: no release activity for more than six years and no recent repository commits indicate likely abandonment.
The latest release was published nearly seven years ago, with no releases in the last twelve months. The nine-release history shows the package once had activity, but not continued maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, with the last push nearly four years ago. This strongly indicates that fixes and compatibility updates may not arrive.
The package declares 11 runtime dependencies, including WordPress tooling, a framework, and application-specific components. This broad dependency surface increases maintenance and compatibility burden for an already inactive project.
The package has no declared license, detected license, or license file in either the artifact or repository. This creates a significant adoption and redistribution concern.
The package defines a pre-install command, so installation executes package-controlled code. That is a supply-chain hygiene concern even though it does not by itself establish malicious behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
timber/timber Version ^1.10 | — | — |
composer/installers Version ^1.6.0 | — | — |
johnpbloch/wordpress Version ^5.1.0 | — | — |
wp-cli/wp-cli-bundle Version * | — | — |
johnbillion/extended-cpts Version ^4.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.