Clear documentation, recent releases, and active work from two contributors support ongoing maintenance. The licensing mismatch and absent security policy leave modest transparency gaps.
84%
Total Score
100
88
75
The artifact contains a GPL-3.0 license file, while the manifest declares GPL-2.0-or-later; because the detected license is not covered by the declaration, this creates a concrete licensing clarification risk.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and maintenance gap rather than evidence of unsafe code.
The repository has no SECURITY.md or other detected security policy, leaving vulnerability-reporting expectations and response processes undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
wp-pay/core Version ^4.34 | — | — |
pronamic/wp-http Version ^1.2 | — | — |
pronamic/pronamic-wp-updater Version ^1.0 | — | — |
automattic/jetpack-autoloader Version ^2.0 || ^3.0 || ^4.0 || ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.