Package Health

middag-io/wordpress

MIDDAG WordPress adapter — persistence, REST, hooks, cron, Inertia frontend, and email for WordPress plugins

Latest v1.14.0PackagistPackagist

72%

Total Score

caution

Usable with caveats: active releases are offset by one maintainer and unpinned workflow actions.

Health Score Breakdown

Lifecycle scriptscaution

The package defines post-install and post-update Composer scripts, which execute during dependency operations and increase installation trust requirements. No provided signal shows those scripts are unsafe, so this is a moderate caution rather than a severe risk.

Repo bus factorcaution

One contributor made 100% of the 105 commits during the last three months. The organization-owned project provides some backing, but no second active contributor is shown, leaving a meaningful continuity risk.

Repo toolingcaution

Composer build tooling is present, but no repository security-scanning tools were detected. The missing scanning is a hygiene limitation rather than evidence of abandonment.

Workflow auditcaution

Both workflows were analyzed with no detected audit findings or untrusted checkouts, but all 11 action references are unpinned and one workflow has top-level write permissions. The workflow_run trigger is ordinary here because no dangerous sink was found.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0
—
—
nyholm/psr7
Version ^1.8
—
—
psr/container
Version ^2.0
—
—
symfony/routing
Version ^7.0 || ^8.0
—
—
firebase/php-jwt
Version ^7.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform