The package is clearly licensed, documented, and backed by repository tests, with no install-time scripts or deprecation notice. Its only release and no commits in three months limit confidence in ongoing maintenance, while all seven workflow actions are unpinned and the audit found a high-confidence template-injection pattern.
64%
Total Score
50
100
83
75
The manifest declares GPL-2.0-or-later, and a LICENSE.md file plus a repository license file are present. The detected GPL-2.0 text is narrower than the declared expression, so the licensing metadata merits a small caution.
The repository is owned by an individual rather than an organization, so the single-person project backing provides limited redundancy if the maintainer becomes unavailable.
This is the only release, published about 223 days after the package first appeared, so there is limited evidence of sustained release maintenance.
The repository recorded no commits and no active maintainers in the last three months. For a package with only one release, this is a meaningful maintenance concern.
There is one open issue and no issue or pull-request activity in the last month. With no recent commits, this adds some evidence of a quiet project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wordpress/wp-ai-client Version ^0.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.