Package Health

tobiasbg/tablepress

TablePress plugin for WordPress

Latest 3.4PackagistPackagist

74%

Total Score

caution

Usable with caveats: active releases, but one-contributor maintenance and workflow issues limit confidence.

Are you affected? Scan for Free

Health Score Breakdown

Repo bus factorcaution

Only one contributor made all 4 commits in the last 3 months, leaving maintenance dependent on a single active person; organization ownership provides some backing but no demonstrated second contributor.

Repo toolingcaution

Composer is used as a build tool, but no security-scanning tools were detected. This is a transparency and preventive-hygiene gap rather than evidence of abandonment.

Security policycaution

The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear for a widely used WordPress plugin.

Workflow auditcaution

All 7 workflows were analyzed, with read-only or job-level permissions in 6 and only 3 of 23 action references unpinned. However, two high-confidence template-injection findings remain in failed-workflow.yml; without an untrusted trigger or checkout, they are workflow hygiene risk rather than a standalone severe dependency-health failure.

Vulnerabilities

TitleVersionsSeverity
CVE-2022-3788
tobiasbg/tablepress is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.0-RC1.
0.0.0 - 2.0-RC1
Medium

Package versions

Maintainers

Tobias Bäthge

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
10 days ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform