ElasticPress 5.3.5 appears to be a healthy, actively maintained dependency. It has a long release history, a current stable release, recent release activity, an unarchived organization-owned repository, substantial recent commit and pull-request activity, multiple active contributors, clear licensing, security policy coverage, and repository build/security tooling. The main concerns are install-time Composer lifecycle scripts and incomplete workflow permission hardening, while the artifact's missing tests and changelog are compensated by their presence in the source repository; these issues warrant review but do not materially undermine the package's overall maintenance or transparency.
86%
Total Score
100
100
100
70
One of 15 workflows uses pull_request_target, which warrants care because that trigger can expose privileged execution paths; however, no untrusted checkouts or script-injection patterns were detected.
The package declares post-install-cmd and post-update-cmd Composer lifecycle scripts, which increase installation-time execution risk and deserve review before adoption.
Ten workflows lack top-level permissions declarations and four declare top-level write permissions, leaving room for least-privilege hardening even though one workflow has read-only permissions and no broader workflow abuse was observed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version 1.0.0 | — | — |
composer/installers Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.