Risky to adopt under this package name because the registry marks the package abandoned and points to woocommerce/action-scheduler. The linked organization-backed repository is active, with a current release, regular commits, and multiple contributors, but new projects should use the replacement package.
40%
Total Score
100
83
75
The package is marked abandoned at package scope, with woocommerce/action-scheduler named as its replacement. This is a substantial adoption risk even though the underlying project remains active.
The repository uses Composer build tooling, but no security scanning tools were detected. This is a modest transparency gap rather than evidence of abandonment.
No repository security policy was found, leaving vulnerability-reporting guidance unclear. The active organization-backed project partially reduces the practical concern but does not remove the gap.
None of the three workflows declares top-level token permissions, which is weaker workflow hardening. No workflow has top-level write permissions, limiting the risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.