The package includes tests, a changelog, a license, and a security policy. Maintenance is concentrated in one contributor, and all three workflow action references are unpinned, but organization backing and frequent releases reduce the concern.
82%
Total Score
88
100
94
75
Post-install and post-update Composer scripts are present. They add execution during installation, but this signal alone does not show unsafe behavior or undermine the package's otherwise strong project evidence.
All 20 recent commits came from one contributor, creating a real continuity risk. The organization-owned repository provides some compensating backing, so this is caution rather than danger.
The repository name does not match the package name and its README does not mention the package. Although the source tree is substantial, this weakens confidence that the linked repository is specifically the package's source.
All three workflows were analyzed successfully with no untrusted checkouts, script injections, or audit findings. However, all three action references are unpinned, and one workflow grants top-level write permissions, creating moderate workflow hygiene concerns.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
owc/zgw-api Version ^2.5 | — | — |
php-di/php-di Version ^7.0 | — | — |
monolog/monolog Version ^3.0 | — | — |
owc/idp-userdata Version ^1.1 | — | — |
woocommerce/action-scheduler Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.