Multi-step quiz plugin using Gutenberg blocks
74%
Total Score
caution
A new, organization-backed package is documented and maintained, but its release history is too short and workflows need hygiene fixes.
This package is extremely new, with two releases arriving about 13 minutes apart and no longer-term release record, so maintenance maturity is not yet demonstrated.
The repository has one star and no forks or watchers, offering little community validation; this is supporting evidence only and does not outweigh the active organizational backing.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency gap for a package with build workflows.
The repository has no security policy, which makes vulnerability reporting and response expectations less clear.
All three workflows were analyzed with pinned actions and no untrusted checkout or script-injection trigger, but the audit found three high-confidence template-injection findings in the release workflow; this is a workflow hygiene concern, not a standalone unfitness signal.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.