The repository has tests, release notes, a clear license, and a security policy. Its very limited release history and no commits in roughly three months leave maintenance continuity uncertain, while workflow references are not pinned.
62%
Total Score
50
88
75
The repository is owned by a user account rather than an organization, so the project has limited visible institutional backing to offset its small maintenance base.
This package is 98 days old and has only one release, so there is little evidence of sustained maintenance or release practice.
There were zero commits and zero active maintainers in the last three months, which is a meaningful maintenance concern for a package whose only release was about three months ago.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest repository hygiene gap.
All 9 analyzed action references are unpinned, which weakens build reproducibility; one workflow also grants top-level write permissions, though the audit found no untrusted triggers, sinks, or high-confidence dangerous findings.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kynetcode/wpzylos-core Version ^1.0 | — | — |
kynetcode/wpzylos-database Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.