The package is clearly licensed and matches an organization-owned repository with a substantial README. Its workflow uses read-only permissions, though one test installs outside a lockfile.
58%
Total Score
50
75
50
The package has five releases since May 2020, but none in the last four years; the latest registry release was in April 2022. This is a substantial maintenance concern despite the historical release cadence.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package having received no release since April 2022. The repository is not archived, but current maintenance capacity is not evident.
There were no new or closed issues or pull requests in the last month, with three issues still open. This supports the broader evidence of inactive project maintenance.
The repository has no security policy, which reduces transparency for reporting and handling security issues. This is a secondary concern because the project is clearly backed and the workflow audit found no high-severity issue.
The single workflow was fully analyzed and uses read-only permissions, with no untrusted checkout or script-injection findings. However, all four action references are unpinned and a high-confidence low-severity finding reports installation outside a lockfile, leaving moderate workflow hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.4 | — | — |
htmlburger/wpemerge Version ~0.17.0 | — | — |
htmlburger/wpemerge-app-core Version ~0.17.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.