The module includes a consumer-facing README, a security policy, and only one runtime dependency. Its long typical release gaps, single recent contributor, unpinned workflow action, and license mismatch warrant checking compatibility and maintenance ownership before adoption.
68%
Total Score
83
100
81
75
The manifest declares GPL-3.0-or-later, while the artifact license file was detected as LGPL-3.0; the release is licensed, but the mismatch needs clarification.
The package has existed for over 11 years and had two releases in the last 12 months, but its median release interval is about 2 years and 1 month, indicating an irregular cadence.
All four recent commits came from one contributor, leaving no demonstrated short-term contributor redundancy; organization backing provides some handoff capacity but does not remove this concentration.
Composer is used for builds, but no security scanning tooling was detected, leaving security-maintenance automation limited.
The only workflow was fully analyzed with no injection or high-severity findings, but its single action reference is unpinned, so it does not provide reproducible action sourcing.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
thelia/installer Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.