The linked repository appears to be a different example template, weakening confidence that it documents and maintains this package. Install-time scripts and the lack of a security policy add operational and transparency concerns, despite clear documentation, tests, and an organizational owner.
35%
Total Score
50
67
50
This package has had only one release, on November 29, 2017, with no releases in the last 12 months. That is strong evidence of an abandoned or frozen dependency.
There were no commits and no active maintainers in the last three months, consistent with a repository that has been inactive for years. This materially increases abandonment risk.
The linked repository is named example-wordpress-composer and neither matches this package nor mentions it in the README. That raises a material concern that this release is attached to a generic or unrelated template repository.
The package runs post-create, post-install, and post-update Composer scripts. These increase installation complexity and execution exposure, though the signal alone does not show that the scripts are unsafe.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no additional adoption or community-maintenance reassurance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^2.4.0 | — | — |
composer/installers Version ^1.3.0 | — | — |
roots/wp-password-bcrypt Version ^1.0.0 | — | — |
wpackagist-theme/twentyseventeen Version ^1.1 | — | — |
rvtraveller/qs-composer-installer Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.