Healthy and suitable to depend on. It has a long release history, frequent recent releases, active repository work, and organization backing; the main caveats are missing security scanning and a security policy, plus install-time Composer scripts.
86%
Total Score
100
100
94
63
The package runs post-install and post-update Composer scripts, which increase installation complexity and require trust in package-controlled automation.
Composer is used as a build tool, but no security scanning tools were detected. The missing scanning reduces assurance about automated security checks without indicating abandonment.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented.
None of the 10 workflows declares top-level permissions, although none declares top-level write access and two use job-level permissions. The configuration is less explicit than ideal but does not show excessive top-level write permissions.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-14675 wpmetabox/meta-box is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 5.11.2. | 0.0.0 - 5.11.2 | High |
| Dependency | Last Release | Score |
|---|---|---|
wpmetabox/support Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.