Liveblogging done right. Using WordPress.
45%
Total Score
unhealthy
The package strongly resembles another owner’s established package, creating a serious identity risk despite active maintenance.
The package is flagged as borrowing the identity of automattic/vipwpcs, a much more downloaded package owned by another publisher. Although artifact overlap is 0.0 and the README does not identify it as that package, the identity signal is a severe adoption risk.
The repository has no published security policy, leaving reporting and response expectations less transparent despite release notes documenting a recent security fix.
All 7 workflows were analyzed, use read-only permissions, and pin all 22 action references. One high-confidence low-severity finding installs a package outside a lockfile, which is a limited hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.