Usable with caveats: it is actively released, licensed, and backed by a current source repository. Maintenance is concentrated in one contributor, and the package has no consumer README or security policy.
74%
Total Score
75
88
67
The package has no README, which is a meaningful transparency and consumer-documentation gap for a theme framework. Missing tests and changelog files are normal for the published artifact, while a GitHub release exists for this version.
All 3 recent commits came from one contributor, so maintenance currently has a fragile single-person dependency. The repository is directly linked to the package, but no second recent contributor provides redundancy.
The project uses Composer build tooling, but no security-scanning tools were detected, leaving a limited automated security-maintenance signal.
No SECURITY.md or equivalent security policy was found, reducing transparency about vulnerability reporting and response.
Both analyzed workflows lack top-level token permissions declarations. They declare no top-level write access, but explicit least-privilege settings are absent.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.