The release includes tests, a changelog, a security policy, and a clear license. Its short history limits confidence, while the repository has no security-scanning tooling.
68%
Total Score
50
88
75
This is a young package, about 97 days old, with two releases and a median interval of about 41 days. That provides some release evidence but leaves limited history for judging long-term maintenance.
All three commits in the last three months came from one contributor, giving the project a single-person maintenance dependency. The repository owner is an individual account, so no organizational handoff evidence offsets that concentration.
Composer build tooling is present, but no security-scanning tools were detected. For a package providing security primitives, that is a meaningful maintenance and assurance gap.
All 9 analyzed action references are unpinned, so workflow dependencies can change without a repository change; one workflow also grants top-level write access. The audit found no untrusted checkout, script injection, or high-confidence dangerous workflow finding.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kynetcode/wpzylos-core Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.