The package has clear setup guidance, a declared license, and no install-time scripts. Recent releases and two merged pull requests support continued maintenance, though no commits were recorded in the last three months and repository security tooling is absent.
78%
Total Score
75
50
89
83
Seven runtime dependencies create a meaningful dependency surface for a testing framework, including PHPUnit and web-related components. This is a manageable caution rather than a severe concern because no dependency-specific failure is shown.
No commits and no active maintainers were recorded in the last three months, which weakens evidence of day-to-day maintenance. The recent release history and two merged pull requests partly compensate for this gap.
The repository has only 1 star and no forks, indicating limited external adoption. Popularity is supporting evidence only, and the organization's backing and release activity compensate for the small public audience.
The repository uses Composer, but no security-scanning tools were detected. Missing scanning lowers transparency and preventive maintenance, though it does not by itself make the package unfit.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a maintenance and transparency gap, not evidence of maliciousness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
10up/wp_mock Version ^1.1 | — | — |
phpunit/phpunit Version ^9.6 | — | — |
symfony/dom-crawler Version ^5.0 | — | — |
symfony/css-selector Version ^5.0 | — | — |
lucatume/function-mocker Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.