This is a reasonably well-scaffolded, licensed, stable-major WordPress plugin with a matching repository, tests, changelog, recent release activity, no deprecation, no install-time lifecycle scripts, and no detected dangerous workflow patterns. However, the repository shows zero commits and zero active maintainers in the last 3 months, the project is maintained by a single individual, has minimal adoption evidence, lacks a security policy, and its workflows do not declare top-level token permissions. These are meaningful transparency and continuity concerns, but not enough to make the release unfit to adopt; review the code and establish an update contingency before relying on it in a critical project.
68%
Total Score
63
100
89
80
Only one registry account has publish access. This is a continuity risk because a single publisher provides limited operational redundancy, and no organization backing is shown by the project_backing signal.
The repository owner is a User rather than an organization, so the single-maintainer concern is not compensated by visible organization backing.
The repository has zero commits and zero active maintainers in the last 3 months. Although the recent release and recent merged pull requests provide some compensating activity, the lack of recent commit activity is a meaningful maintenance-continuity concern.
The repository has only 1 star and 1 fork, with 0 watchers. Popularity is supporting evidence rather than a verdict, but these counts provide little external evidence of broad review or adoption.
Composer is used as a build tool, but no security scanning tools are present. The absence of scanning lowers assurance for a dependency, though it is a hygiene gap rather than evidence of unsafe code by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yahnis-elsts/plugin-update-checker Version ^5.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.