Agentic AI loop for WordPress — chat with an AI that can call WordPress abilities (tools) autonomously.
68%
Total Score
caution
Active releases and organization backing offset one-contributor maintenance and 32 of 36 unpinned workflow actions.
One contributor made 100% of the 342 commits during the last three months. Organization ownership provides some ability to hand off maintenance, but no second active contributor is shown.
The repository recorded 342 commits in three months, demonstrating very active development, but all commits came from one active maintainer.
The repository name does not match the package name, and the README does not mention the Packagist package. Although a monorepo or renamed project can explain this, the linkage is not clearly demonstrated by the provided evidence.
Composer is used for builds, but no security-scanning tool was detected in the repository. This is a transparency and preventive-hygiene gap, not evidence of a defect.
All 9 workflows were analyzed with no audit findings, no untrusted checkouts, and no script injection; however, 32 of 36 action references are unpinned, leaving avoidable build-reproducibility and action-substitution risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
x-wp/di Version dev-fix/rest-context-plain-permalink-support as 1.9.99 | — | — |
psr/simple-cache Version ^1.0 || ^2.0 || ^3.0 | — | — |
smalot/pdfparser Version ^2.12.5 | — | — |
automattic/jetpack-autoloader Version ^5.0.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.