The release is clearly licensed, matches its source repository, and has a small dependency footprint. Organization backing and a clean workflow audit help, but the project offers little evidence that maintenance is still active.
47%
Total Score
50
100
75
75
Only two releases were published, both in June 2022, with no release in roughly four years. This strongly increases abandonment risk for a package developers may need to maintain over time.
There were zero commits and zero active maintainers in the last three months, consistent with roughly four years since the last push. This is strong evidence that maintenance capacity is currently absent.
There were no new or closed issues or pull requests in the last month, with no open backlog. The clean issue state is mildly positive, though it may also reflect the project's very small and inactive user base.
Composer is used for builds, but no security scanning tools are configured. The build tooling supports reproducibility, while the missing scanning is a modest transparency and hygiene gap.
The linked repository is not archived, but its last push was in June 2022. The active repository status is mildly reassuring while the stale activity remains the larger concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sitepilot/wp-theme Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.