This is a generally healthy, actively maintained release: the package has existed for over 10 years, has 34 releases including 11 in the last 12 months, was released recently, is stable rather than prerelease, is not deprecated, and is backed by a non-archived organization-owned repository with a matching package name. The main concerns are concentrated maintenance, with all four commits in the last 3 months coming from one contributor, and limited project documentation and testing evidence: neither the artifact nor repository contains tests, and the artifact has no README or changelog, although the repository does contain a README and uses GitHub Releases. The repository also lacks a security policy and does not declare top-level workflow permissions, so the package is suitable to depend on with normal review but is not completely risk-free.
78%
Total Score
90
50
89
80
Seven runtime dependencies create a meaningful dependency surface, including several related organization packages, but the provided profile does not show an unusually large or evidently unmanaged dependency set.
The artifact lacks a README, tests, and changelog, and the repository also lacks tests; however, the repository does contain GitHub Releases, which partly compensates for the missing changelog and provides release transparency.
Only one contributor was active in the last 3 months and that contributor made 100% of recent commits, creating a genuine continuity risk. Organization backing partly mitigates handoff risk, but no second active contributor is shown.
The repository has only 1 star and no forks, indicating limited external adoption, but popularity is supporting evidence rather than a health verdict and does not outweigh the active release history.
No repository security policy is present, leaving vulnerability-reporting expectations undocumented. This is a transparency gap, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpseclib/phpseclib Version ^3.0.0 | — | — |
helsingborg-stad/wpservice Version ^2.0 | — | — |
helsingborg-stad/acfservice Version ^1.0 | — | — |
helsingborg-stad/wputilservice Version ^0.3 | — | — |
helsingborg-stad/acf-export-manager Version ^1.0.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.