Package Health

thelia/keyword-module

Recent releases and seven commits in three months show ongoing maintenance. Organization backing and a second active contributor help offset concentrated commit activity, though workflow hygiene is basic.

Latest 4.0.0PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Licensecaution

The artifact declares LGPL-3.0+ but its detected license file is GPL-3.0, so the licensing information does not clearly align even though a license file is present.

Repo package mentioncaution

The linked repository is named Keyword and does not mention this package in its README, which creates some uncertainty that it is the intended source repository.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tooling was detected, leaving a modest transparency and hygiene gap.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.

Workflow auditcaution

The single workflow was fully audited with no injection or high-severity findings, but its one action reference is unpinned; the absence of a top-level permissions block is acceptable on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Michaël Espeche

Direct Dependencies

DependencyLast ReleaseScore
thelia/installer
Version ~1.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform