Package Health

joedolson/my-calendar

My Calendar WordPress Plugin

Latest v3.8.7PackagistPackagist

72%

Total Score

caution

Usable with caveats: all recent repository activity comes from one contributor.

Are you affected? Scan for Free

Health Score Breakdown

Repo bus factorcaution

All 320 commits in the last three months came from one contributor, giving the project a high single-maintainer continuity risk despite its strong activity level.

Security policycaution

The repository has no published security policy, leaving vulnerability reporting and response expectations less transparent for users of this plugin.

Workflow auditcaution

All five workflows were analyzed successfully with no detected injection, untrusted checkout, or high-confidence audit findings, and no workflow grants top-level write access. However, all 14 analyzed action references are unpinned, which weakens build reproducibility and supply-chain integrity.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-40308
joedolson/my-calendar is vulnerable to Authorization Bypass Through User-Controlled Key in versions 0.0.0 - 3.7.7.
0.0.0 - 3.7.7
High

Package versions

Maintainers

Joe Dolson

Direct Dependencies

DependencyLast ReleaseScore
composer/installers
Version ~1.0
—
—

Weekly Downloads

Info

Last Published
6 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform