The project is young and lightly adopted, with one registry maintainer and two repository stars. It has clear documentation, tests, a changelog, and a recent release, which support a bounded trial.
62%
Total Score
50
100
94
75
Only one account has registry publish access, limiting publishing redundancy. The linked repository is user-owned rather than organization-backed, so there is no visible organizational compensation.
The repository recorded zero commits and zero active maintainers in the last three months, despite a recent package release. That weakens evidence of ongoing maintenance.
The repository has only 2 stars, 2 forks, and 1 watcher, providing little evidence of broad external review or adoption. Low popularity is supporting evidence, not proof of poor quality.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a moderate transparency gap for a WordPress plugin.
All five analyzed action references are unpinned, which leaves the build exposed to changing action contents. The workflow has no untrusted checkout or script-injection findings, so this is a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.