This release appears healthy and suitable for dependency use: it has a long release history, recent publishing activity, stable versions, an active and non-archived repository, current commits from two contributors, repository tests and changelog coverage, and no install-time lifecycle scripts. The main weaknesses are limited security transparency and workflow hardening: no security policy or repository security scanning was observed, and the CI workflow does not declare top-level token permissions. These are meaningful hygiene gaps but do not outweigh the package's demonstrated maintenance, organizational backing, and release continuity.
88%
Total Score
100
100
94
80
The repository uses Composer build tooling, but no security-scanning tools were detected. The missing security scanning is a genuine supply-chain hygiene gap, though it is not evidence of maliciousness or abandonment.
No repository security policy was found. This reduces vulnerability-reporting transparency, but it is a hygiene gap rather than evidence that the package is unsafe or unmaintained.
The single CI workflow lacks top-level token permissions, so its effective permissions are less explicitly constrained than preferred. No workflow was observed with explicitly declared write permissions, which limits the severity of this concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wp-pay/core Version ^4.28 | — | — |
pronamic/wp-http Version ^1.2 | — | — |
pronamic/wp-mollie Version ^2.0 | — | — |
pronamic/wp-number Version ^1.4 | — | — |
justinrainbow/json-schema Version ^5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.