The package includes tests, release notes, and a security policy. Organization backing and a current release provide continuity, although the repository lacks security scanning and its workflow audit has limited coverage.
72%
Total Score
75
94
100
The repository has no commits and no active maintainers in the last 3 months, which is a maintenance concern. The current release and a push today partly compensate, so this is caution rather than severe abandonment evidence.
Composer is used as a build tool, but no security scanning tools were detected. That leaves a meaningful repository hygiene gap for a package intended to be adopted as a dependency.
The single workflow was fully analyzed with no dangerous findings or untrusted checkouts, but all 4 action references are unpinned. The missing top-level permissions block is acceptable on its own, while unpinned actions remain a supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
alleyinteractive/wp-type-extensions Version ^5.0 | — | — |
alleyinteractive/composer-wordpress-autoloader Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.