Healthy and suitable to use, with a thin recent contributor base as the main caveat. It has a long release history, releases roughly every 10 days, an active unarchived repository, and clear security and build practices.
82%
Total Score
63
100
90
The top contributor made all 5 commits in the last 3 months, leaving no demonstrated second active contributor. Organization backing provides some handoff capacity, but the recent activity is still concentrated.
There were 5 commits in the last 3 months, showing recent activity, but all activity came from only one active maintainer.
The repository still merges pull requests, with 4 merged in the last month and 2 issues closed, although there were no new issues or pull requests during that period and 61 issues remain open.
One workflow declares write permissions for publishing, which is consistent with a release workflow, but the security-scan workflow lacks top-level permissions and is less explicit than ideal.
| Title | Versions | Severity |
|---|---|---|
CVE-2022-4905 wpcloud/wp-stateless is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.2.0. | 0.0.0 - 3.2.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ^6.1.2 | — | — |
ccampbell/chromephp Version ^4.1 | — | — |
composer/installers Version ~2.3 | — | — |
udx/lib-wp-bootstrap Version ^1.3 | — | — |
udx/lib-ud-api-client Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.