Clear documentation, repository tests, release notes, and organization backing make the package straightforward to assess. Its stable version, license, security policy, and modest dependency profile are reassuring, though workflow hygiene needs attention.
62%
Total Score
75
100
94
100
The package has 13 releases since February 2022, but none in the last 12 months. That recent release gap lowers confidence in ongoing maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Although a recent push is recorded elsewhere, the observed recent development activity is currently absent.
All 3 analyzed action references are unpinned, and the audit found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow. The pull_request_target workflow has no untrusted checkout or script-injection sink, limiting the impact to workflow hygiene rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
alleyinteractive/wordpress-autoloader Version ^1.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.