The package has a clear license, repository tests, release notes, and active organizational ownership. Workflow permissions and inherited secrets need attention, while recent repository activity is quiet despite a recent release.
60%
Total Score
75
100
86
50
The artifact includes license files and declares GPL-2.0-or-later, but the detected GPL-2.0 text is narrower than the declaration, creating a licensing inconsistency.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, although the package had a release in May 2026 and a repository push in June 2026.
Composer is used for builds, but no security-scanning tooling was detected, leaving a modest transparency and maintenance gap.
The repository has no published security policy, which makes vulnerability reporting less transparent for a library used in WordPress plugins.
The sole workflow grants top-level write permissions, uses one unpinned action, and has a high-confidence medium-severity secrets-inherit finding. No untrusted checkout or script injection was detected, so this is a hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
publishpress/pimple-pimple Version ~3.2 | — | — |
alledia/edd-sl-plugin-updater Version ^1.6.24 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.