Healthy and suitable to use, with a few transparency and maintenance caveats. It has a long release history, five releases in the last year, active repository updates, tests, and organization backing, but recent commits come from one contributor and the repository does not clearly identify the package in its README.
78%
Total Score
75
100
88
80
One contributor made all five commits in the last three months, creating a meaningful continuity risk. Organization ownership provides some ability to hand maintenance off, but no second active contributor is shown.
Five commits were made in the last three months, so maintenance is active, although all were made by one maintainer.
The repository name does not match the package name, and no README package mention was collected. Although a name mismatch can be normal for a module repository, the absence of a confirming mention creates some uncertainty about package-to-repository alignment.
Composer is used as a build tool, but no security scanning tools were detected. The missing scanning is a modest transparency gap, not evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability-reporting guidance unclear. This is a transparency weakness, partially offset by the package's active release and repository activity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
thelia/installer Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.