The package has a declared GPL-2.0 license, a readable README, release notes, and a modest runtime dependency set. Its workflows use five unpinned actions, and the repository has no security policy.
42%
Total Score
0
100
75
50
Only one release exists, published about five years and eight months ago, with none in the last 12 months. This is strong evidence of abandonment risk for a WordPress plugin.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap and leaving compatibility work unverified.
post-install-cmd and post-update-cmd scripts run during Composer operations, adding execution during installation and updates. The signal provides no evidence that these scripts are unsafe, so this is a limited supply-chain hygiene concern.
The repository has no security policy, making the process for reporting and handling vulnerabilities unclear. This matters for a plugin that runs inside WordPress sites.
All five analyzed action references are unpinned, which weakens build reproducibility. The audit found no untrusted checkouts, script injection, dangerous triggers, or top-level write permissions, so this remains a hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/container Version ^2.4 | — | — |
mustache/mustache Version ^2.13 | — | — |
composer/installers Version ~1.0 | — | — |
screenfeed/autowpoptions Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.