Documentation and licensing are in good shape, and the package has a small, focused dependency set. Its ongoing maintenance depends on one contributor, while build workflows use broad permissions and unpinned actions.
68%
Total Score
75
100
100
50
Post-install and post-update scripts run during dependency operations, adding execution surface beyond ordinary file installation and warranting extra trust in the publisher.
All 15 recent commits came from one contributor, so maintenance and release knowledge are concentrated in a single person.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
All seven analyzed action references are unpinned, and two of three workflows grant top-level write permissions. The audit found no untrusted checkouts, script injection, or high-confidence findings, so this is workflow hygiene risk rather than a severe issue.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-stubs/wordpress-stubs Version ^5.3 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.