The release is clearly documented, licensed, actively updated, and has a focused dependency set. Maintenance depends on one contributor, while workflow permissions and unpinned actions leave avoidable supply-chain hygiene gaps.
67%
Total Score
67
100
94
50
post-install-cmd and post-update-cmd scripts run during Composer operations, adding execution exposure beyond ordinary package loading. No provided signal shows these scripts are harmful, so this is a hygiene concern rather than a severe risk.
Only one account has registry publish access. The linked repository is user-owned rather than organization-backed, so there is no provided organizational capacity to compensate for this concentrated publishing responsibility.
All 14 recent commits came from one contributor, leaving no demonstrated backup maintainer. The active commit rate helps, but the repository is user-owned and provides no organizational handoff capacity.
Composer build tooling is present, but no security scanning tools were detected. For a small generated-stub package this is a modest transparency and maintenance gap, not evidence of unsafe code.
The repository has no security policy. That weakens vulnerability-reporting transparency, although the package's narrow stub-focused role limits the practical impact.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-stubs/wordpress-stubs Version ^5.3 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.