The package is clearly identified, licensed, documented, and has no install-time scripts. Its small scope is understandable, but the project has not yet demonstrated sustained maintenance or security-process maturity.
68%
Total Score
50
88
75
This is the first and only release, published 0 days ago, so there is no release track record yet. That limits evidence of maturity but does not by itself show abandonment.
There were 0 commits and 0 active maintainers in the last 3 months, so sustained maintenance is not demonstrated. Because the package itself is 0 days old, this is limited evidence rather than proof of abandonment.
Composer is used as the build tool, but no security scanning tools were detected. For a small WordPress plugin this is a modest process gap, not a severe dependency risk.
The repository has no security policy, reducing transparency about vulnerability reporting and response.
No GitHub Actions workflows were present, so there are no workflow risks to flag. This also means there is no observed automated CI or release assurance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.