Five contributors made 22 commits in the last three months, and releases remain frequent. The package includes tests and has no install-time scripts, but workflow pinning and security documentation could be stronger.
67%
Total Score
100
100
81
67
The manifest declares GPL-3.0-or-later, while the artifact license file is detected as MIT; although both the artifact and repository contain license files, this unresolved mismatch creates legal uncertainty.
The linked repository name does not match the package name and its README does not mention the package, so ownership of the published package is not clearly established.
Composer build tooling is present, but no security-scanning tooling was detected; the missing scanner is a modest transparency gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented and reducing maintenance transparency.
The sole workflow was fully analyzed with no reported audit findings or untrusted-code sinks. Its one action reference is unpinned, which is a minor reproducibility and supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
thelia/installer Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.