University of Colorado Boulder base theme
72%
Total Score
100
78
80
A substantive README and changelog are present, and the README documents installation and linting. Tests are absent from both the artifact and repository, which is a modest hygiene gap for a theme package but not by itself a severe dependency risk.
The linked repository name does not match the package name and its README does not mention the package, creating a meaningful risk that the repository relationship is unclear or that the package is using a broader project repository. The README excerpt references boulder_base and the repository is a CU Boulder theme repository, which partially explains the naming difference but does not remove the provenance uncertainty.
The repository has only 3 stars and no forks, so external adoption evidence is limited. Popularity is supporting evidence rather than a decisive health requirement, especially given the active release and commit signals.
Composer is used as a build tool, but no security scanning tools were detected. The missing scanning coverage is a transparency and assurance gap, though it is partly offset by the active repository and safe workflow analysis.
No repository security policy was found, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.