Healthy and suitable to use. It has frequent recent releases, active maintenance by three contributors in an organization-owned repository, and a clear README; the main caveats are missing security-policy documentation and undeclared top-level workflow token permissions.
86%
Total Score
100
100
94
80
The project uses Composer build tooling, but no security-scanning tool was detected. This is a modest transparency and maintenance gap, not a severe risk given the active repository and simple dependency profile.
The source repository has no security policy. That weakens vulnerability-reporting transparency, although active commits and recent releases provide compensating maintenance evidence.
The release workflow does not declare top-level token permissions. Explicit least-privilege permissions would improve release security and reproducibility, so this is a workflow-hardening concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
thelia/installer Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.