Composer plugin that installs WordPress core (packages of type wordpress-core) into a directory of your choice.
62%
Total Score
caution
A first-day release with one contributor and unpinned workflow actions leaves maintenance and build-reproducibility concerns.
This is a brand-new package released 0 days ago with only one release, so there is no track record for maintenance or stability yet.
One contributor made 100% of the observed commits, creating a concentrated maintenance base; organization backing partly offsets that risk.
Only 1 commit was observed in the last 3 months, so there is very little actual maintenance activity to establish continuity.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and assurance gap for a new package.
The repository has no security policy, which is a minor transparency gap for a package that can alter a project's WordPress installation.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.