Release activity stopped over four years ago, and the package also resembles a more established package while borrowing its identity. MIT licensing, tests, documentation, and a matching organization repository are positives, but they do not offset the maintenance risk.
15%
Total Score
0
33
50
The package borrows the identity of roots/wp-config, has no fork disclosure, and is much less downloaded than that package; consumers may have intended the lookalike instead.
Packagist marks the entire package as abandoned and points consumers to roots/acorn-prettify, making continued dependency use a serious lifecycle risk.
The latest release was published in August 2022, with no releases in the following four years; this strongly indicates the package has been left behind.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the archived and abandoned status.
The linked GitHub repository is archived, so it is no longer an actively maintained upstream despite having been pushed in January 2024.
| Title | Versions | Severity |
|---|---|---|
CVE-2022-4524 roots/soil is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 4.1.0. | 0.0.0 - 4.1.0 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.