Risky to adopt: the package has had no release or repository activity for more than eight years. It is licensed, minimally scoped, correctly backed by its organization repository, and has no install-time scripts, but its long-term abandonment risk is substantial.
42%
Total Score
50
100
67
100
The latest release was published on December 8, 2017, with no releases in the last 12 months. More than eight years without a release is strong evidence of abandonment risk, even for a small plugin.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long period without releases. This materially lowers confidence that compatibility or defects will be addressed.
The repository uses Composer build tooling, but it has no security scanning tools. For this small WordPress plugin this is a hygiene gap, though it is secondary to the much more significant inactivity.
The repository is not archived, which avoids the strongest abandonment signal, but its last push was on December 8, 2017 and does not offset the prolonged inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.