The project is actively maintained, with six releases in the past year and 41 recent commits from four contributors. Licensing needs clarification, and the repository lacks a security policy while its sole workflow uses an unpinned action.
82%
Total Score
100
100
88
75
The artifact declares GPL-3.0-or-later but its license file is detected as LGPL-3.0; although both the artifact and repository contain license files, the mismatch warrants clarification.
Composer is used for builds, but no security scanning tool is reported, leaving a modest transparency gap in automated security hygiene.
The linked repository has no security policy, so its process for reporting and handling vulnerabilities is not documented.
The only workflow was fully analyzed with no dangerous sinks or audit findings. However, its single action use is unpinned; the lack of a top-level permissions block is not a concern on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
thelia/installer Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.