It has clear installation and usage documentation, a stable 2.0 release, and organizational ownership. The single dependency and absence of install scripts reduce integration surprises, but workflow pinning and security documentation remain limited.
64%
Total Score
75
100
88
75
The package has 24 releases since 2017, but none in the past 12 months. That indicates maintenance has slowed for a package with a long history, though the established release record provides some maturity evidence.
The repository recorded zero commits and zero active maintainers in the past 3 months. This is direct evidence of limited recent development capacity and increases the risk that issues or compatibility needs will remain unattended.
Composer is used as a build tool, but no security scanning tools were detected. The missing scanning is a hygiene limitation rather than evidence that the package is unsafe or unmaintained by itself.
The repository has no security policy. This makes vulnerability reporting and project response expectations less transparent, adding a modest maintenance and transparency concern.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. Its only action reference is unpinned, which weakens build reproducibility but is not a severe workflow risk on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
thelia/installer Version ~1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.