It has a clear README, a release note for 3.0.0, one runtime dependency, and no install-time scripts. The organization-backed repository is active and unarchived, but lacks security scanning and pins one workflow action loosely.
71%
Total Score
83
100
94
83
All five recent commits came from one contributor, leaving maintenance highly concentrated. Organization backing provides some handoff capacity, but no second recent contributor is shown.
Composer is used for builds, but no security scanning tools are present. This is a maintenance and transparency gap, though not evidence of an unsafe release by itself.
The repository has no security policy, leaving vulnerability reporting expectations undocumented.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, its one action reference is unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
thelia/installer Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.