This is a mature, established package with nearly ten years of release history, a stable major version, a recent release, active non-archived organization-backed repository, and no registry deprecation. The main concerns are that repository commit activity has been absent for 3 months, issue and pull-request queues show no recent resolution, the package and repository lack tests and a changelog, and the release workflow does not declare top-level token permissions. These are meaningful maintenance and transparency gaps, but they are moderated by the recent release, matching repository, build and security tooling, clean workflow analysis, and organization ownership; the package appears usable but should be adopted with normal maintenance and update monitoring.
78%
Total Score
75
100
89
80
Neither the artifact nor repository contains tests or a changelog, and the artifact lacks a README; the repository does have GitHub Releases, which provides some release transparency but does not compensate for the testing gap.
The repository recorded 0 commits and 0 active maintainers during the last 3 months. This is concerning for maintenance responsiveness, but it is partly offset by the release published immediately before collection.
There is 1 open issue and 8 open pull requests, with no new or closed issues and no merged pull requests in the last month. The unresolved queue is a maintenance warning, though it is not by itself evidence of abandonment.
The repository has no stars or forks and only 9 watchers, indicating limited external adoption and review. Popularity is supporting evidence rather than decisive, so this lowers confidence and maturity assessment modestly.
No SECURITY.md or equivalent security policy was found, reducing vulnerability-reporting transparency for dependents.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
helsingborg-stad/wpservice Version ^2.0 | — | — |
helsingborg-stad/wputilservice Version ^0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.