Usable with caveats: the package is licensed, documented, stable, and backed by a matching organization repository, but it has had no release or commit activity since February 2023. Treat it as a largely inactive dependency and verify compatibility before adopting it.
55%
Total Score
63
50
88
88
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the multi-year release gap and indicating stalled maintenance.
The package has eight runtime dependencies, including deployment, database, media, and WordPress tooling components. This is a relatively broad dependency surface for deployment tasks and increases compatibility maintenance needs, though it is consistent with the package's stated purpose.
The package has 13 releases and a typical historical interval of about 50 days, but its latest release was in February 2023 with no releases in the last 12 months. The long release gap is a meaningful maintenance concern.
There is only one open issue and no recent issue or pull-request activity, offering little evidence of current project engagement.
Composer is used as the build tool, but no security-scanning tooling is reported. The missing scanning is a transparency and maintenance gap, although it is not evidence that the package is malicious.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wp-cli/wp-cli Version ~2.1 | — | — |
symfony/dotenv Version ^3.3 || ^4 || ^5 || ^6 | — | — |
deployer/deployer Version ~7.0 | — | — |
sourcebroker/deployer-loader Version ^4 | — | — |
wp-cli/search-replace-command Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.