Clear documentation and a small dependency footprint reduce adoption friction. The clean workflow audit and organization ownership add reassurance, while the limited project history leaves less evidence about long-term support.
68%
Total Score
67
100
88
75
This release is from a package only 48 days old, with one release total, so long-term maintenance is not yet demonstrated. The repository has recent activity, which partly offsets the limited history.
One contributor made 100% of the seven commits in the last three months, creating a concentrated continuity risk. Organization ownership provides some ability to hand off maintenance, so this is a caution rather than a severe risk.
Seven commits were made in the last three months, showing current activity. However, all seven came from one active maintainer, limiting evidence of broader maintenance capacity.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning is a modest transparency gap rather than evidence of abandonment.
The repository has no security policy, reducing clarity about vulnerability reporting and response. This is a hygiene weakness, but it is partly outweighed by the active repository and organization backing.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
thelia/installer Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.