Regular releases and three active contributors provide good maintenance coverage. MIT licensing and release notes are clear, but workflow references remain unpinned and the repository identity needs verification before adoption.
68%
Total Score
100
50
89
50
The scaffold declares 24 runtime dependencies, including WordPress, WP-CLI, plugins, and deployment components; this breadth increases update and compatibility surface but fits the package's stated project-stack role.
The package runs a post-root-package-install Composer script. For a WordPress project scaffold this can be expected, but it adds install-time behavior that consumers should understand.
The linked repository is named dudestack and neither matches the package name nor mentions ronilaukkarinen/wpstack-rolle in its README, so package-to-source ownership should be verified.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, which makes vulnerability reporting and maintenance expectations less clear for a package with many runtime dependencies.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
oscarotero/env Version ^2.1 | — | — |
roots/wp-config Version ^1.0 | — | — |
vlucas/phpdotenv Version ^5.3 | — | — |
composer/installers Version ^1.10.0 | — | — |
johnpbloch/wordpress Version 7.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.