Recent commits, two active contributors, tests, and a GitHub release show ongoing project work. The license files disagree, and the repository does not identify this package, adding avoidable adoption and traceability concerns.
42%
Total Score
100
71
67
Packagist marks the entire package deprecated and names thelia/predict-module as its replacement. This is a direct warning against starting a new dependency on this package, even though the repository remains active.
The manifest declares GPL-3.0-or-later while the artifact license file is detected as LGPL-3.0. Both are explicit licenses, but the mismatch should be resolved before relying on the package's licensing terms.
The repository name does not match the package name and its README does not mention this package, so the linkage is not clearly established. A monorepo can explain a name mismatch, but the absent README mention remains a traceability concern.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is secondary to the package's deprecation.
The sole workflow was fully analyzed with no injection or high-severity findings, but its one action reference is unpinned, leaving avoidable reproducibility and action-integrity risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
thelia/installer Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.