Recent commits and releases show active maintenance, with organization backing and security tooling adding resilience. Workflow permissions and seven unpinned action references are modest hygiene concerns, but the audit found no dangerous workflow findings.
88%
Total Score
100
100
100
All 9 workflows were analyzed with no audit findings, untrusted checkouts, or script-injection counts. Five workflows grant top-level write access and 7 of 13 action references are unpinned, creating a modest reproducibility and permissions-hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wp-cli/wp-cli Version ^3.0 | — | — |
wp-cli/package-command Version ^2 || ^3 | — | — |
wp-cli/scaffold-command Version ^2 || ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.