This is a transparently packaged, stable-major WordPress utility library with a clear README, changelog, license, source repository, matching package references, repository tests, and no install-time scripts or registry deprecation. However, it is young at 134 days, has only one registry maintainer, no repository commits or active maintainers in the last 3 months despite a recent push and rapid release cadence, and lacks security scanning and a security policy. The zero-star and zero-fork repository is consistent with a new package rather than decisive evidence of poor quality, but the maintenance and security-process gaps warrant caution before adopting it as a critical dependency.
68%
Total Score
50
100
83
90
Only one registry account has publish access, creating a limited publishing and continuity base. The linked repository is owned by the same individual rather than an organization, so there is no provided organizational backing to offset this risk.
The source repository is owned by a personal GitHub account, not an organization. The repository does directly back the package, but the individual ownership leaves less demonstrated continuity than organizational backing would provide.
Eighteen releases in 134 days, with a median interval of about 12 hours, show active publication and responsiveness, though the short history provides limited evidence of long-term durability.
The repository records zero commits and zero active maintainers over the last 3 months, which is a meaningful maintenance concern. The recent push and frequent registry releases partially offset the concern but do not establish sustained source-development activity.
There are no open issues or pull requests and no recent issue or pull-request activity. This is not inherently unhealthy for a small library, but it offers little evidence of an engaged maintenance community.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
woocommerce/action-scheduler Version ^3.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.