Maintenance has stopped since February 2023, with no recent commits or releases, and five issues remain open. The project is still licensed, tested, unarchived, and its workflows use read-only permissions, which limits the concern.
58%
Total Score
50
90
50
The package has had no releases in the last 12 months, and its latest release was published in February 2023. This is a meaningful maintenance concern for a dependency, although the six-release history shows it was previously maintained.
There were zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository is not archived, but observed activity provides no evidence of current maintenance.
Five issues remain open, with no issues closed and no pull requests merged in the last month. This adds to the evidence of inactivity, though it does not by itself show the package is unusable.
The repository has no security policy. This weakens vulnerability-reporting transparency, but it is a secondary concern compared with the clear maintenance slowdown.
Both workflows use read-only permissions and the audit found no injection sinks or other reported findings. All six action references are unpinned, a modest reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/plates Version ^3.3 | — | — |
hashids/hashids Version ^2.0 || ^3.0 || ^4.0 | — | — |
ssnepenthe/metis Version ^0.6 | — | — |
composer/installers Version ^1.0 | — | — |
ssnepenthe/wp-requirements Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.