The artifact includes a license and changelog, while recent publishing and commits show ongoing work. Its installer hook fits a Composer project, but the project has little operating history.
64%
Total Score
67
92
83
The repository owner is a user account rather than an organization, so there is no provided evidence of organizational maintenance capacity to offset the concentrated contributor base.
The package has 16 releases in 21 days, showing active publishing but a very short operating history. That supports current activity without yet demonstrating long-term reliability.
One contributor made all 10 commits during the last three months, leaving no demonstrated handoff capacity if that maintainer becomes unavailable.
The repository has no security policy. That reduces transparency for reporting and handling vulnerabilities in a package intended to install a full application stack.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
websyspro/devtools Version ^1.0 | — | — |
websyspro/wpengine Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.