This release appears usable but is not yet a mature, broadly transparent dependency. The repository is active, unarchived, has 19 commits from two contributors in the last three months, includes tests, and has a stable non-prerelease version with no registry deprecation. However, the package is only 62 days old, has very low repository adoption, highly concentrated contribution activity, no README or changelog, no security policy or security scanning, and a proprietary manifest license that limits its fit for projects expecting an open-source dependency. Overall, adoption is reasonable with maintainer due diligence, but the package carries meaningful maturity, documentation, governance, and continuity risks.
68%
Total Score
63
100
72
90
The package declares a proprietary license in its manifest, so this is not a missing-license transparency gap; however, the proprietary terms may be unsuitable for projects requiring an open-source license.
Tests exist both in the artifact and repository, and GitHub Releases provide some release documentation coverage. The missing README and changelog still reduce usability and transparency for a package intended to be adopted as a dependency.
The repository is owned by a personal GitHub account rather than an organization account. This does not establish inadequate backing, but it means the concentrated contributor activity has less visible organizational redundancy to compensate for it.
The package is young at 62 days with four releases, and its recent release cadence is very rapid, with a median interval of about 49 minutes. This demonstrates activity but leaves limited evidence of long-term maintenance and may indicate rapid iteration.
Two contributors are active, but the leading contributor made 16 of 19 commits, or about 84%, leaving maintenance substantially concentrated. The second contributor provides some continuity but does not eliminate the bus-factor concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
woocommerce/action-scheduler Version ^3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.