The repository is clearly linked and the package is licensed under GPL-3.0-or-later. Its Composer lifecycle hooks and lack of a security policy add transparency concerns for a payment integration.
42%
Total Score
0
75
67
The package has had no release in over two years, despite 46 releases since 2019; that long gap is a substantial abandonment concern for a payment integration.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the release gap and indicating no current maintenance activity.
The package runs pre- and post-install/update Composer scripts. These add installation-time behavior that deserves review, although the signal alone does not show malicious or unsafe commands.
Composer is used for builds, but no security scanning tools were detected. That is a modest transparency and maintenance weakness rather than proof of a defect.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities in a payment integration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
claudiosanches/wp-git-hooks Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.