The repository has active recent work, four contributors, tests, and an organization behind it. The license text conflicts with the declared license, and its single workflow uses an unpinned action.
82%
Total Score
100
100
88
83
The package declares GPL-3.0-or-later, but the artifact license file was detected as GPL-2.0. Although a license file is present and the repository also has one, the mismatch needs clarification before adoption.
The project uses Composer, but no security-scanning tooling was detected. The missing scanner is a hygiene gap, while the build tooling itself is appropriate for this package.
The single workflow was fully audited with no untrusted checkouts, script injections, or high- or medium-confidence findings. Its one action is unpinned, which leaves update integrity weaker, while the absence of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
thelia/installer Version ^1.6 | — | — |
thelia/thelia-blocks-module Version ^3.0 | — | — |
thelia/thelia-library-module Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.