Healthy and suitable to depend on. It has regular releases, recent commits from three contributors, tests, release notes, and clear organization backing; the main caveat is incomplete workflow permission hardening and no automated security scanning.
91%
Total Score
100
94
88
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and preventive-maintenance gap, though it is not outweighed by the package's otherwise strong maintenance evidence.
One workflow lacks top-level permissions and another declares top-level write permissions; although no dangerous workflow patterns were detected, narrower explicit permissions would improve CI hardening.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-foundation Version ^v7.2 | — | — |
alleyinteractive/wp-type-extensions Version ^2.0|^3.0|^4.0|^5.0 | — | — |
alleyinteractive/composer-wordpress-autoloader Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.