Healthy and reasonable to depend on. It has a long release history, frequent recent releases, active repository contributors, tests, documentation, and current release notes. Review the repository's broad workflow permissions and lack of a security policy before adopting it in a security-sensitive project.
82%
Total Score
90
100
100
50
One of four workflows uses pull_request_target, which can increase CI security exposure, although no untrusted checkouts or script-injection patterns were detected.
There are 40 open issues and no issues closed in the last month, which is a modest maintenance concern, but five pull requests were merged during that period.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
Three workflows omit top-level token permissions and one workflow grants top-level write access, reducing least-privilege transparency for automation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
10up/elasticpress Version ~5.3.4 | — | — |
humanmade/debug-bar-elasticpress Version ~1.6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.