Package Health

thelia/admin-comment-module

The module includes a consumer-facing README, a security policy, and only one runtime dependency. Its long typical release gaps, single recent contributor, unpinned workflow action, and license mismatch warrant checking compatibility and maintenance ownership before adoption.

Latest 3.0.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Licensecaution

The manifest declares GPL-3.0-or-later, while the artifact license file was detected as LGPL-3.0; the release is licensed, but the mismatch needs clarification.

Release historycaution

The package has existed for over 11 years and had two releases in the last 12 months, but its median release interval is about 2 years and 1 month, indicating an irregular cadence.

Repo bus factorcaution

All four recent commits came from one contributor, leaving no demonstrated short-term contributor redundancy; organization backing provides some handoff capacity but does not remove this concentration.

Repo toolingcaution

Composer is used for builds, but no security scanning tooling was detected, leaving security-maintenance automation limited.

Workflow auditcaution

The only workflow was fully analyzed with no injection or high-severity findings, but its single action reference is unpinned, so it does not provide reproducible action sourcing.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
thelia/installer
Version ^1.6
—
—

Weekly Downloads

Info

Last Published
3 hours ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform