Onboarding of new users, site- and user creation for a WordPress Multisite network like figuren.theater.
61%
Total Score
caution
A 10-month-old release, no recent commits, and four unpinned workflow actions keep this package in the caution range.
Nine runtime dependencies make this a relatively broad integration package, which increases the maintenance surface, though the dependency list is explicit.
The package has 12 releases since February 2024, but only 1 release in the last 12 months and the latest release is about 10 months old, indicating a slow cadence.
The repository had zero commits and zero active maintainers in the last 3 months, which is meaningful evidence of currently inactive maintenance.
No security policy is present. This is a transparency gap, although the package's Dependabot configuration provides some compensating security-maintenance coverage.
All 4 analyzed workflows use unpinned actions, and all 4 have high-confidence medium-severity secrets-inherit findings. There are no untrusted checkouts or script injections, but the combination leaves workflow supply-chain and credential-scope hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
stuttter/wp-multi-network Version 2.5.2 | — | — |
stuttter/wp-user-profiles Version 2.6.2 | — | — |
figuren-theater/ft-options Version * | — | — |
figuren-theater/install.php Version 1.4.0 | — | — |
wpackagist-plugin/impressum Version 2.0.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.