The release cadence is modest, while installation runs a Composer post-autoload hook. The repository could not be found, leaving maintenance and provenance unverifiable.
12%
Total Score
60
50
The manifest declares GPL-2.0-or-later, but the artifact contains detected MIT license text, creating a material licensing mismatch despite having license files.
The readme identifies the package as a fully activated premium copy from wordpress-premium.net and documents a license code that is automatically restored, indicating an unauthorized repackaging rather than a trustworthy upstream release.
The package runs a post-autoload-dump install-time script. This is not inherently unsafe, but it adds execution during installation to an artifact whose provenance is already difficult to verify.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.