A clear README, release notes, recent commits, and organization backing improve transparency and continuity. The missing security policy leaves disclosure guidance unclear.
66%
Total Score
83
100
100
67
All 15 commits in the last 3 months came from one contributor, giving the project a bus factor of one. Organization ownership provides some handoff capacity, but the observed maintenance base remains narrow.
The repository has no security policy or documented disclosure path. For a WordPress plugin with REST and access-control features, that is a transparency gap.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings, and one scopes permissions at job level. However, all 10 analyzed action references are unpinned, leaving avoidable workflow supply-chain drift.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.