Package Health

thelia/cms-module

Documentation, tests, release notes, and recent source work make the package easier to adopt. The license files need clarification against the declared license, and the repository has no security policy or automated security scanning. Pin the alpha version deliberately because compatibility may change before 1.0.

Latest 1.0.0-alpha.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Licensecaution

A license is present in the artifact and repository, but the declared LGPL-3.0-or-later does not exactly match the detected LGPL-3.0 and GPL-3.0 license texts, which warrants clarification.

Release historycaution

This package is only 54 days old and has one release, so there is little release history to demonstrate sustained maintenance or compatibility stability.

Repo bus factorcaution

One contributor made about 98% of the 127 recent commits, leaving maintenance highly concentrated despite a second active contributor and organization ownership.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving a meaningful verification gap for a package with substantial application functionality.

Security policycaution

The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
thelia/installer
Version ~1.6
—
—
symfony/html-sanitizer
Version ^7.4
—
—
thelia/thelia-library-module
Version dev-twig
—
—
openstudio/page-builder-bundle
Version ^0.2.1
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform