Clear documentation, licensing, and release notes make this small plugin straightforward to evaluate. Its workflows have weak pinning and credential-handling hygiene, and the repository lacks a security policy.
56%
Total Score
50
100
89
67
Only one registry account has publish access. With individual repository ownership and sparse recent activity, this suggests a thin publishing and continuity base.
The repository is owned by an individual rather than an organization, so the single registry maintainer provides limited visible backing for long-term continuity.
Only two releases are recorded, with none in the last four years; the long release interval is a meaningful maintenance concern despite the repository having a more recent push.
There were no commits and no active maintainers in the last three months, weakening the evidence of current maintenance despite the more recent historical push.
The project uses Make and Composer, but no security-scanning tooling was detected, leaving a modest transparency and hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
textpattern/lock Version >=4.7.0 | — | — |
textpattern/installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.