Recent releases and seven commits in three months show ongoing maintenance. Organization backing and a second active contributor help offset concentrated commit activity, though workflow hygiene is basic.
70%
Total Score
100
100
81
75
The artifact declares LGPL-3.0+ but its detected license file is GPL-3.0, so the licensing information does not clearly align even though a license file is present.
The linked repository is named Keyword and does not mention this package in its README, which creates some uncertainty that it is the intended source repository.
Composer build tooling is present, but no security-scanning tooling was detected, leaving a modest transparency and hygiene gap.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
The single workflow was fully audited with no injection or high-severity findings, but its one action reference is unpinned; the absence of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
thelia/installer Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.