Package Health

thelia/order-comment-module

Recent releases and active work from an organization-backed project support continued maintenance. The missing security policy and concentrated commits add modest transparency and continuity concerns.

Latest 3.0.1PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Licensecaution

The artifact declares GPL-3.0-or-later but its license file was detected as LGPL-3.0, creating a licensing clarification concern despite the presence of license files in both artifact and repository.

Security policycaution

The repository has no security policy, leaving reporting and response expectations undocumented; this is a transparency gap rather than evidence of unsafe code.

Workflow auditcaution

The single workflow was fully audited with no injection or high-severity findings, but its one action reference is unpinned, allowing the referenced action to change over time.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
thelia/installer
Version ^1.6

Weekly Downloads

Info

Last Published
7 hours ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform