Configure admin-side user-group privileges
58%
Total Score
caution
The last registry release was over four years ago, and its workflows use unpinned actions with high-confidence credential-handling findings.
Both workflows were analyzed successfully, but all 9 action references are unpinned, and the CI workflow has two high-confidence artipacked findings because checkout credentials are not explicitly disabled. These are material release-process hygiene risks.
The package has four releases since March 2015, with no registry release in the last four years; this indicates a meaningful maintenance slowdown despite the linked repository being updated more recently.
There were no commits and no active maintainers in the three months before collection. This conflicts with the more recent repository push and lowers confidence in ongoing development capacity.
The repository uses Make and Composer, but no security scanning tools were detected. This is a hygiene gap rather than evidence that the package is unsafe.
No security policy was found in the repository, reducing transparency around vulnerability reporting and maintenance response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
textpattern/lock Version >=4.7.0 | — | — |
textpattern/installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.