The WordPlate boilerplate
78%
Total Score
50
100
50
The package runs a post-root-package-install script. This is an install-time behavior that deserves awareness, but the provided signal does not show harmful or unusually broad actions.
One contributor made all 5 commits in the last 3 months, giving the repository a 100% top-contributor share. As a user-owned project rather than an organization-owned repository, this concentration is a meaningful resilience concern.
There were 5 commits in the last 3 months and 1 active maintainer, showing recent work but a narrow maintenance base. The activity is positive, while the concentration adds some abandonment risk.
The repository has no security policy. For a WordPress boilerplate handling application dependencies and configuration, this reduces the clarity of vulnerability-reporting expectations.
All workflows were analyzed with no reported audit findings, no untrusted checkouts, and no script injection. However, both referenced actions are unpinned, leaving a minor reproducibility and action-supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
roots/wordpress Version ^7.1 | — | — |
vinkla/headache Version ^3.6 | — | — |
vlucas/phpdotenv Version ^5.6 | — | — |
composer/installers Version ^2.3 | — | — |
symfony/http-foundation Version ^8.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.