Package Health

wp-pay/core

The package has a long release history, recent changes, and ongoing repository work. CI uses five unpinned actions, and the repository has no security policy, but organization backing and a second active contributor reduce maintenance risk.

Latest v4.35.0PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Are you affected? Scan for Free

Health Score Breakdown

Security policycaution

The repository has no SECURITY.md or other recorded security policy, leaving vulnerability reporting and response expectations less transparent.

Workflow auditcaution

The single workflow was fully analyzed with no reported audit findings or untrusted sinks, but all 5 action references are unpinned, which weakens build reproducibility and action integrity.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2025-10207 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
wp-pay/core is vulnerable to Improper Input Validation in versions 4.4.0 - 4.25.3.
4.4.0 - 4.25.3
Medium

Package versions

Maintainers

Pronamic
Remco Tolsma

Direct Dependencies

DependencyLast ReleaseScore
pronamic/wp-html
Version ^2.2
—
—
pronamic/wp-http
Version ^1.2
—
—
pronamic/wp-money
Version ^2.5
—
—
pronamic/wp-number
Version ^1.4
—
—
pronamic/wp-datetime
Version ^2.2
—
—

Weekly Downloads

Info

Last Published
6 days ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform