Shared WordPress must-use bootstrap and development utilities for SymPress websites.
72%
Total Score
caution
A brand-new package has no recorded three-month commit activity, though its repository is structured and actively prepared for release.
The manifest declares GPL-2.0-or-later, the artifact includes license files, and the repository also has a license file. The detected MIT text alongside GPL-2.0-or-later is worth checking for scope, but this is not an unlicensed release.
The package is brand new, with three releases in less than a day and no longer-term release history. This limits evidence of sustained maintenance but is partly expected for a new release.
The repository records zero commits and zero active maintainers over the last three months. Because the package was released today and was pushed today, this is a meaningful coverage and continuity concern rather than proof of abandonment.
The single workflow was fully analyzed, uses read-only permissions, and has no audit findings or untrusted triggers. Both action references are unpinned, a modest reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sympress/kernel Version ^1.1.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.