The package includes tests, a substantial README, stable versioning, and organization backing. Its three-month commit gap, absent security policy, and unpinned workflow action leave maintenance and release hygiene concerns.
68%
Total Score
75
100
88
67
The package is young at 197 days with three releases and a median interval of about 99 days, showing activity but limited history for judging long-term maintenance.
There were no commits and no active maintainers in the last three months, a meaningful maintenance warning despite the recent release and one merged pull request.
Composer build tooling is present, but no security scanning tools were detected, leaving automated security hygiene less transparent.
The repository has no security policy, making the process for reporting and handling vulnerabilities unclear.
The single workflow was fully analyzed with no dangerous findings or untrusted checkout, but its one action is unpinned and the workflow has no top-level permissions block; these are limited release-hygiene concerns.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
thelia/installer Version ^1.6 | — | — |
thelia/thelia-library-module Version ^2.0.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.