The MIT license and substantial README support straightforward use. CI has no dangerous audit findings, but its three action references are unpinned and the repository has no security policy.
58%
Total Score
67
86
50
The package has 49 releases, but all were published in a single day and there have been no releases in the last 12 months. That concentrated history and prolonged release gap raise abandonment concern.
The repository recorded zero commits and zero active maintainers during the last 3 months, consistent with the long release gap and indicating weak current maintenance.
There were no new or closed issues or pull requests in the last month. This supports the inactivity concern, although a quiet project can also reflect limited support demand.
The linked repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is not evidence of a security defect by itself.
All three workflows were analyzed with no dangerous findings and no broad top-level write permissions, but all 3 of 3 action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wp-cli/wp-cli Version ^2.12 | — | — |
composer/semver Version ^1.4 || ^2 || ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.