The repository shows recent activity from two contributors under organizational ownership, and this release includes notes and a usable README. The single unpinned workflow action and absent security policy leave modest transparency and build-hygiene gaps.
68%
Total Score
100
100
81
67
This package is 49 days old and has only one release, so there is little evidence yet of sustained maintenance or release reliability.
The repository name does not match the full package name and its README does not mention the package, so the link is less transparent even though a submodule naming difference can be ordinary.
Composer is used for builds, but no security scanning tool is present, leaving a modest verification gap.
The repository has no security policy, which reduces transparency about vulnerability reporting and handling.
The sole workflow was fully analyzed with no dangerous triggers or audit findings, but its only action reference is unpinned, so build inputs are less reproducible.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
thelia/installer Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.