The package is small and easy to inspect, with a README and a repository that clearly matches it. Missing security scanning and a security policy reduce transparency, while the limited project activity leaves little evidence of ongoing support.
38%
Total Score
0
50
75
75
The package has only two releases, with the latest published about eight years ago and no releases in the last 12 months. This is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with its last push being in 2018. No provided signal shows compensating recent maintenance.
The manifest declares one runtime dependency with the same name as the package, which may indicate a packaging or installation mistake rather than a meaningful external dependency. This warrants caution for consumers.
The repository has two stars and no forks, providing little evidence of an active user or contributor community. Popularity is supporting evidence only, but it does not offset the stale activity.
Composer is used for the build, which fits the ecosystem, but no security scanning tools are present. That leaves supply-chain and dependency hygiene less visible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wpkenpachi/wpdecodejson Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.