The package includes repository tests, a clear MIT license, release notes for this version, and active organization backing. Its recent commit silence and fully unpinned workflow actions leave maintenance and build-integrity concerns.
68%
Total Score
75
100
83
There were no commits and no active maintainers in the past three months, despite a recent release. That gap lowers confidence in ongoing maintenance capacity.
The repository has no security policy. For a framework package used in WordPress projects, this is a transparency gap, although it is not evidence of an active security problem.
All four workflows were analyzed without detected high-confidence findings or dangerous triggers, but all 12 action references are unpinned. The missing top-level permissions blocks are acceptable on their own, while unpinned actions create a modest build-integrity concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pinkcrab/perique-framework-core Version 2.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.