Documentation, release notes, and recent commits provide useful maintenance evidence. The organization-backed repository is active, but install scripts and release-workflow credential and template risks warrant care.
65%
Total Score
88
100
94
50
post-install-cmd and post-update-cmd scripts run during Composer operations, increasing installation-time behavior and review burden compared with a passive configuration package.
All nine recent commits came from one contributor. Organization ownership provides some handoff capacity, but the observed maintenance base remains concentrated.
Composer build tooling is present, but no security-scanning tools were detected, leaving a repository security-process gap.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
All three workflows were analyzed successfully, but the release workflow has high-confidence template-injection findings, secrets-inherit usage, top-level write permissions, and four of nine unpinned actions. The trigger and sink counts are zero, so this is workflow hygiene and credential exposure risk rather than a standalone severe verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slevomat/coding-standard Version ^8.0 | — | — |
wp-coding-standards/wpcs Version ^3.0 | — | — |
squizlabs/php_codesniffer Version ^3.7 || ^4.0 | — | — |
silverassist/coding-standards Version ^1.0 | — | — |
phpcompatibility/phpcompatibility-wp Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.