The stable release, active organizational ownership, and matching repository documentation provide useful continuity. Build workflows use unpinned actions, and the project has no security policy or scanning, leaving avoidable maintenance and transparency concerns.
55%
Total Score
75
86
50
The package defines post-install and post-update Composer scripts, which add install-time behavior and therefore a modest supply-chain and reproducibility concern.
The package has 20 releases over about 5 years, but none in the last 12 months; the long gap weakens confidence in ongoing maintenance despite its established history.
There were zero commits and zero active maintainers during the last 3 months, consistent with the long release gap and indicating currently quiet maintenance.
Composer build tooling is present, but no security scanning tools were detected, leaving a meaningful quality and security-process gap for a dependency.
The repository has no security policy, reducing transparency about vulnerability reporting and maintainer response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wp-pay/core Version ^4.16 | — | — |
pronamic/wp-money Version ^2.4 | — | — |
automattic/jetpack-autoloader Version ^3.0 || ^4.0 || ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.