TablePress plugin for WordPress
74%
Total Score
caution
Usable with caveats: active releases, but one-contributor maintenance and workflow issues limit confidence.
Only one contributor made all 4 commits in the last 3 months, leaving maintenance dependent on a single active person; organization ownership provides some backing but no demonstrated second contributor.
Composer is used as a build tool, but no security-scanning tools were detected. This is a transparency and preventive-hygiene gap rather than evidence of abandonment.
The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear for a widely used WordPress plugin.
All 7 workflows were analyzed, with read-only or job-level permissions in 6 and only 3 of 23 action references unpinned. However, two high-confidence template-injection findings remain in failed-workflow.yml; without an untrusted trigger or checkout, they are workflow hygiene risk rather than a standalone severe dependency-health failure.
| Title | Versions | Severity |
|---|---|---|
CVE-2022-3788 tobiasbg/tablepress is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.0-RC1. | 0.0.0 - 2.0-RC1 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.