Unfit to use: the package is deprecated and its source repository is archived. It has no release activity for about two and a half years, so ongoing fixes and support should not be expected despite the documented, licensed project structure.
15%
Total Score
33
40
75
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct indication that new projects should not depend on it.
The latest registry release was published about two and a half years ago, and there were no releases in the last 12 months. That lack of distribution activity materially increases the risk of depending on an obsolete template.
The repository had zero commits and zero active maintainers during the last three months. This confirms that there is no recent development activity to offset the abandonment signals.
The linked source repository is archived, which is a severe abandonment signal even though it was pushed recently. Archived projects generally should not be expected to receive ongoing maintenance.
The repository is owned by an organization and is clearly tied to the package namespace, which provides stronger ownership context than an unbacked project. That positive context is outweighed by the deprecated organization and archived repository state.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^3.1.0 | — | — |
composer/installers Version ^1.3.0 | — | — |
roots/wp-password-bcrypt Version ^1.0.0 | — | — |
wpackagist-plugin/lh-hsts Version ^1.24 | — | — |
wpackagist-theme/twentynineteen Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.