The project has only one release and no commits or active contributors in the last three months. Organization backing, a matching repository, and a small dependency set provide useful support, but workflow permissions and unpinned actions need attention.
63%
Total Score
75
100
88
75
This is the package's only release, published about 10 months ago, so there is little release history to establish sustained maintenance.
There were no commits and no active maintainers in the last three months, which is a meaningful maintenance concern for a package with only one release.
Composer is used for the build, but no security scanning tools were detected; this is a modest transparency and hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented.
All four action references are unpinned, and the audit found a high-severity, low-confidence cache-poisoning pattern plus a high-confidence secrets-inherit finding. The workflows were fully analyzed and have no untrusted checkout or script-injection findings, which limits the concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kucrut/vite-for-wp Version ^0.12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.