This is a generally usable and well-established package: it has been published since 2017, has 98 releases including 8 in the last 12 months, remains on a stable major version, is not deprecated, and is backed by a non-archived organization-owned repository. The main concerns are that repository commit activity was absent over the last 3 months, the package and repository have no tests or changelog, the repository lacks a security policy, and its workflow does not declare top-level token permissions. Low popularity and a single registry maintainer are moderated by the organization backing and strong release history, so this is a caution-level dependency rather than an obviously unfit one.
72%
Total Score
88
100
89
80
The artifact and repository have no tests or changelog, and the artifact has no README; the repository does contain a README and uses GitHub Releases, which partly compensates for documentation and release-note gaps. The absence of tests remains a genuine maintenance-transparency concern.
The repository recorded 0 commits and 0 active maintainers over the last 3 months. This is a meaningful maintenance slowdown, though it conflicts with the recent release and push evidence in other signals.
The repository has only 2 stars, 1 fork, and 9 watchers, indicating a small user and contributor footprint. Popularity is supporting evidence rather than decisive, but this modest visibility reduces external resilience.
No security policy was found in the repository. This leaves vulnerability reporting and response expectations undocumented, creating a modest transparency gap.
The release workflow lacks top-level permissions and instead uses job-level permissions, with no read-only workflow classification. Although no top-level write permissions were detected, the incomplete declaration reduces workflow hardening transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
helsingborg-stad/wpservice Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.