The repository has tests, release notes, and recent activity, but maintenance capacity is thin. Avoid making this a new dependency unless its behavior is required and you can maintain the integration yourself.
44%
Total Score
67
100
75
75
Packagist marks the entire package as abandoned with no replacement, which is a major adoption risk even though the linked repository remains available.
The registry has published no release in nearly five years, although the repository was pushed recently; this indicates stale distribution rather than complete project disappearance.
All recent repository commits came from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown in this period.
Only one commit from one active maintainer was recorded in the last three months, showing limited recent maintenance capacity despite the recent repository push.
The linked repository has no security policy, leaving vulnerability-reporting expectations undocumented for a package that operates inside WordPress sites.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.