The stable release includes release notes, repository tests, and no runtime dependencies. The project lacks a security policy, and recent work is concentrated in one contributor despite current activity.
68%
Total Score
75
100
86
83
The package has only two releases across about 16 months, with one release in the last 12 months and roughly 15 months between releases. This suggests a small, slowly released project, though the recent release shows it is not abandoned.
All 11 recent commits came from one contributor, giving the project a bus factor of one. Because the owner is an individual rather than an organization, this meaningfully increases continuity risk.
Composer build tooling is present, but no security-scanning tools were detected. For a small WordPress plugin this is a modest transparency gap rather than evidence of unsafe code.
The repository has no security policy. That leaves vulnerability reporting and response expectations undocumented, which modestly lowers transparency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.