The project includes tests, a changelog, a license, and a matching organization-owned repository. Its same-day release history leaves maintenance unproven, while all 11 workflow actions are unpinned and no security policy is present.
66%
Total Score
75
88
75
The package has four releases in about 12 hours, with a median interval of about 1 hour. This shows active initial publishing but provides no longer-term maintenance record.
The repository shows zero commits and zero active maintainers over the last three months. Because the package and repository are only about a day old, this is mainly an unproven maintenance record rather than strong abandonment evidence.
Composer build tooling is present, but no security scanning tool was detected. This is a modest transparency and hygiene gap.
The repository has no security policy. For a WordPress malware-scanning tool, the missing disclosure process is a meaningful transparency gap.
Both workflows were analyzed successfully with no dangerous audit findings or untrusted triggers, and one scopes permissions at job level. However, all 11 action uses are unpinned, leaving workflow dependencies exposed to tag or ref changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.