The linked project has tests, release notes, a license, and organization backing. Packagist abandonment, no recent registry releases, and workflow credential-sharing make this a poor default dependency; use only if you control the scaffold.
42%
Total Score
75
75
67
Packagist marks the entire package abandoned, with no replacement listed. This is a substantial adoption and maintenance risk despite evidence of an active source repository.
The package has eight releases since 2017, but none in the last 12 months and the latest registry release was in January 2024. That weakens confidence in receiving maintained published updates.
The repository recorded no commits and no active maintainers in the three months before collection. The later recorded push shows the project is not abandoned outright, but recent development remains thin.
The repository has no security policy. For a scaffold that may be copied into production plugins, this is a transparency gap, though it is not severe on its own.
Version 0.5.0 is not a prerelease, but the package remains below a stable major version. This is a modest maturity concern for a scaffold intended to seed new projects.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kucrut/vite-for-wp Version ^0.5.2 | — | — |
illuminate/pagination Version ^8.83 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.