This is a mature, actively maintained and clearly identified package: it has been released since 2017, has 56 releases including 8 in the last 12 months, is stable, not deprecated, and its repository was updated very recently. The artifact is licensed, has substantial documentation, and corresponds directly to a repository with extensive tests and build tooling, while the package has no install-time lifecycle scripts. The main concerns are that all 14 commits in the last 3 months came from one contributor, the repository has no security policy, and its sole workflow lacks top-level token permissions; these reduce resilience and security transparency but do not outweigh the strong maintenance and provenance evidence.
82%
Total Score
75
100
94
80
The repository is owned by a user rather than an organization, so the concentrated maintainer activity is not mitigated by visible organizational backing.
One contributor made all 14 commits in the last 3 months, creating a genuine single-maintainer continuity risk for a user-owned project.
Composer build tooling is present, supporting reproducible project management, but no security scanning tools were detected, leaving a modest security-process gap.
The repository has no security policy, reducing vulnerability-reporting transparency and maintainer guidance for security issues.
The sole workflow lacks top-level token permissions declarations. Although no top-level write permissions were observed, explicit least-privilege configuration would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
automattic/vipwpcs Version ^3.0.1 | — | — |
wp-coding-standards/wpcs Version ^3.4.1 | — | — |
phpcsstandards/phpcsextra Version ^1.0.2 | — | — |
squizlabs/php_codesniffer Version ^3.13.2 | — | — |
sirbrillig/phpcs-variable-analysis Version ^2.12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.