Advanced Security Add-on, powered by Patchstack
72%
Total Score
caution
Usable with caveats: active maintenance is reassuring, but weak package-to-repository matching and CI hygiene reduce confidence.
The repository name does not exactly match the package name and its README does not mention the package, so the package-to-source relationship is less explicit than expected despite the matching repository URL.
No repository security policy was found, leaving vulnerability-reporting guidance less transparent for a security-focused package.
All seven analyzed action references are unpinned, and two high-confidence template-injection findings plus an ad hoc package installation weaken CI hygiene. The pull_request_target workflow has no untrusted checkout or script-injection finding, so this is caution rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wpackagist-plugin/patchstack Version ^2.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.