The package is small and focused, with a clear license and security policy. Pin v2.23.1 while its release automation and maintenance coverage mature.
71%
Total Score
67
100
100
67
The package runs post-install and post-update Composer scripts. These add install-time execution risk and deserve review because their behavior is not shown here.
All recent commits came from one contributor, leaving maintenance highly concentrated despite the repository being organization-owned.
Only two commits were recorded in the last three months, which shows some recent activity but limited maintenance capacity.
Both workflows were analyzed and all seven action references are pinned, but a high-confidence template-injection finding remains in the release workflow; without an untrusted trigger or checkout it is a hygiene concern rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
php-stubs/wordpress-stubs Version >=5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.