Clear documentation, tests, release notes, and a small dependency set support adoption. A single active contributor, no security policy, and several unpinned workflow actions leave continuity and build-hygiene risks.
82%
Total Score
67
100
100
67
The registry namespace and repository owner both identify the same individual account, and the repository is user-owned. This confirms ownership alignment but provides no organizational backing to offset the concentrated bus factor.
One contributor made all 9 commits in the last 3 months, representing a 100% top-contributor share. The project is user-owned rather than organization-owned, so this concentration is a real continuity risk.
No repository security policy was found. For a WordPress plugin, the absence of a documented vulnerability-reporting process reduces transparency and response confidence.
All 4 workflows were analyzed successfully with no reported audit findings, no untrusted checkouts, and no script injection; three scope permissions at job level and one use read-only permissions. However, 6 of 10 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.