It has clear organizational ownership, a matching repository, a permissive license, and release notes for this version. The repository has no security policy, while the release workflow checks untrusted code and uses unpinned actions. Recent registry releases provide some evidence of ongoing publishing despite no commits in the last three months.
68%
Total Score
67
100
100
50
A post-update-cmd script runs during Composer updates, which adds some installation complexity but is not by itself evidence of poor package health.
The repository recorded zero commits and zero active maintainers in the last three months, indicating a recent maintenance slowdown.
There are no open issues and one open pull request, but no issues or pull requests were closed or merged in the last month, offering little evidence of active maintenance.
The repository has no SECURITY.md or other declared security policy, reducing transparency for vulnerability reporting.
All three workflows were analyzed successfully, but the release workflow checks out untrusted code and all 8 action references are unpinned. No high-confidence audit findings or broad top-level write permissions were reported.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ooksanen/acf-focuspoint Version ~1.2.0 | — | — |
helsingborg-stad/wpservice Version ^2.0 | — | — |
helsingborg-stad/acfservice Version ^1.3 | — | — |
helsingborg-stad/acf-export-manager Version >=1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.