It also has tests, release notes, security reporting, and broad contributor activity. Check the GPL-2.0-or-later declaration against the GPL-3.0 license text before adoption; workflow findings are hygiene concerns.
84%
Total Score
100
93
67
The artifact includes license files, but the manifest declares GPL-2.0-or-later while the detected license is GPL-3.0. That mismatch warrants checking the applicable licensing terms.
post-install-cmd and post-update-cmd scripts run during Composer installation or updates, adding execution-time supply-chain exposure even though lifecycle scripts can be legitimate for PHP packages.
All 13 workflows were analyzed without failures. One high-confidence script-injection finding is a workflow hygiene concern; the workflow_run trigger is in a different workflow, and the low-confidence cache findings carry little weight. Thirty of 80 action references are unpinned, a minority rather than an across-the-board gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wp-media/mcp-oauth Version 1.1.1 | — | — |
composer/installers Version ^1.0 || ^2.0 | — | — |
voku/simple_html_dom Version ^4.8 | — | — |
wp-media/wp-mixpanel Version ^1.4.4 | — | — |
wp-media/plugin-family Version 1.0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.