The package includes tests, a changelog, release notes, and a clear license. Its organization-backed repository remains active, though its broad dependency set and missing security policy add modest maintenance overhead.
79%
Total Score
100
50
92
50
The package declares 37 runtime dependencies spanning payment gateways and WordPress integrations. That breadth is appropriate for its plugin story but increases update and transitive-dependency maintenance exposure.
Composer post-install-cmd and post-update-cmd scripts run during dependency operations. These are a supply-chain and installation-review consideration, although the active, structured package provides some compensating project context.
Composer build tooling is present, but no security-scanning tool was detected. The build process is established, while automated security coverage is not evident.
The linked repository has no security policy. This reduces disclosure transparency for a payment-related integration, although it does not by itself show abandonment or unsafe code.
All 4 workflows were analyzed successfully with no audited findings, no untrusted checkouts, no script injection, and no broad top-level write permissions. However, all 9 action references are unpinned, leaving avoidable action-supply-chain drift risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wp-pay/core Version ^4.35 | — | — |
pronamic/wp-html Version ^2.2 | — | — |
pronamic/wp-http Version ^1.2 | — | — |
pronamic/wp-money Version ^2.5 | — | — |
pronamic/wp-number Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.