Documentation, tests, release notes, and recent source work make the package easier to adopt. The license files need clarification against the declared license, and the repository has no security policy or automated security scanning. Pin the alpha version deliberately because compatibility may change before 1.0.
68%
Total Score
83
75
75
A license is present in the artifact and repository, but the declared LGPL-3.0-or-later does not exactly match the detected LGPL-3.0 and GPL-3.0 license texts, which warrants clarification.
This package is only 54 days old and has one release, so there is little release history to demonstrate sustained maintenance or compatibility stability.
One contributor made about 98% of the 127 recent commits, leaving maintenance highly concentrated despite a second active contributor and organization ownership.
Composer build tooling is present, but no security scanning tools were detected, leaving a meaningful verification gap for a package with substantial application functionality.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
thelia/installer Version ~1.6 | — | — |
symfony/html-sanitizer Version ^7.4 | — | — |
thelia/thelia-library-module Version dev-twig | — | — |
openstudio/page-builder-bundle Version ^0.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.