Clear documentation, tests, and release notes make integration easier. The sole-contributor project has sensible dependencies and security tooling, but lacks a security policy and leaves half of workflow actions unpinned.
78%
Total Score
70
100
100
83
Only one registry account has publish access, which creates publishing concentration, though the linked repository shows the same individual actively maintaining it.
The repository is owned by an individual rather than an organization, so the single-contributor and single-publisher concentration is not offset by visible organizational backing.
All three recent commits came from one contributor, leaving maintenance dependent on a single active developer.
The repository has no documented security policy, leaving vulnerability-reporting and response expectations unclear.
Both workflows were fully analyzed with job-level permissions and no untrusted checkout or script-injection findings. Four of eight action references are unpinned, and the auditor reported only low-confidence cache-poisoning hygiene findings, so this is a minor caution rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^2.0 | — | — |
woocommerce/action-scheduler Version ^3.7 | — | — |
yahnis-elsts/plugin-update-checker Version ^5.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.