Healthy and suitable to depend on. It has a long, regular release history, an active non-archived repository with recent commits from three contributors, strong project backing, tests, and release notes. Workflow permissions and pull-request automation deserve routine review but do not outweigh the maintenance evidence.
94%
Total Score
100
100
100
80
Two workflows use pull_request_target, which warrants review because that trigger can expose elevated repository privileges, but no untrusted checkout or script injection was detected.
Five workflows declare top-level write permissions and two omit top-level permissions, creating a broader-than-ideal automation privilege posture despite one read-only workflow.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wp-cli/wp-cli Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.