Healthy and reasonable to adopt, with a young project and a narrow active contributor base as the main caveats. It has recent releases, tests, clear source backing, minimal runtime dependencies, and no deprecation or dangerous workflow findings.
78%
Total Score
83
100
89
75
All three recent commits came from one contributor, creating a real continuity risk. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for maturity, but the package is only 86 days old and popularity alone does not outweigh its active releases and organization backing.
The repository uses Composer build tooling, but no security scanning tools were detected; this is a transparency and maintenance gap rather than evidence of an unsafe release.
No repository security policy was found, leaving vulnerability-reporting expectations unclear for a package intended for integration into WordPress projects.
All three workflows omit top-level token permissions, so their required access is not explicitly constrained. No workflow declares top-level write access, which limits the severity of this gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.