It includes a substantial test suite, clear documentation, and matching MIT licensing. The single registry maintainer and absent security policy leave limited independent assurance.
70%
Total Score
83
100
88
50
The package has existed for about four years with 10 releases and a median interval of about 75 days, but only one release appeared in the last 12 months. The latest release is recent, so this suggests slower maintenance rather than abandonment.
There were no commits and no active maintainers in the last three months. The recent release and repository push provide some compensation, but the current maintenance gap remains a concern.
The repository uses Composer but reports no security scanning tools, leaving less automated assurance than a mature project might provide.
The repository has no security policy, so users have no documented reporting or response process visible in the collected evidence.
All four workflows were analyzed without dangerous triggers, sinks, or audit findings, but all 9 action references are unpinned. The workflows also omit top-level permissions blocks, which is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
woocommerce/action-scheduler Version 3.9.* | — | — |
pinkcrab/perique-framework-core Version 2.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.