Package Health

offsite-solutions/tholos

This is a usable but relatively young package with strong recent release activity, a non-archived organization-owned repository, and a substantial artifact and README. The main concerns are that the package has no declared or file-based license, lacks tests and a changelog both in the artifact and repository, has no security policy or security scanning, and all recent repository commits come from one contributor. Active releases and organizational backing reduce abandonment risk, but the transparency, validation, and bus-factor gaps justify caution before adopting it as a critical dependency.

Latest 1.0.26PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

The package declares 14 runtime dependencies, including a framework, database-related extensions, spreadsheet/PDF libraries, and multiple PHP extensions; this is a meaningful operational dependency surface, though not inherently unhealthy for the documented framework's scope.

Licensecaution

No declared license and no license file were found in the artifact or repository, leaving the legal terms for use unclear; this is a genuine transparency concern.

Package scaffoldingcaution

The package has a substantial README, but it has no tests or changelog, and the repository also lacks both; the repository's GitHub Releases provide some release communication but do not replace validation coverage.

Repo bus factorcaution

One contributor made all 24 recent commits, creating a concentrated bus-factor risk. Organization ownership partially compensates because maintenance can potentially be handed off, but no second active contributor is shown.

Repo commit activitycaution

The repository recorded 24 commits in the last 3 months, indicating active development, but all activity came from one active maintainer, limiting independent maintenance evidence.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Offsite Solutions Ltd.

Direct Dependencies

DependencyLast ReleaseScore
mpdf/mpdf
Version 8.3.1
—
—
phpoffice/phpspreadsheet
Version 5.*
—
—
offsite-solutions/eisodos
Version @dev
—
—
azurre/php-array-xml-converter
Version 0.5.1
—
—

Weekly Downloads

Info

Last Published
27 days ago
Created
12 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform