It has a README, changelog, release notes, stable version, and focused dependency set. Organization backing and a matching repository add transparency, while missing security tooling leaves some assurance gaps.
67%
Total Score
83
100
88
83
The package has had five releases since October 2023, but none in the last 12 months; the latest release was in June 2025. This indicates a meaningful maintenance slowdown for a plugin that may need compatibility updates.
The repository recorded zero commits and zero active maintainers in the last three months. Together with the absent releases in the last year, this supports a caution about current maintenance capacity.
The repository uses Composer, but no security-scanning tools were detected. This is a transparency and assurance gap, though it is not evidence of unsafe code by itself.
The repository has no security policy. That weakens the documented process for reporting and handling vulnerabilities, especially for a plugin used in payment-related integrations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pronamic/pronamic-wp-updater Version ^1.0 | — | — |
automattic/jetpack-autoloader Version ^3.0 || ^4.0 || ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.