Regular releases and a current, non-archived source support continued maintenance. The package is licensed, has a useful README, and uses no install-time scripts, but verify the repository identity before adopting it.
67%
Total Score
83
100
88
83
One contributor made all 6 commits in the last 3 months, leaving maintenance highly dependent on a single person; organization backing provides some handoff capacity but no second active contributor is shown.
The repository name does not match the package name and its README does not mention the package, so the source-to-package relationship is not clearly established.
Composer build tooling is present, but no security scanning tools are reported, leaving a modest transparency and maintenance-process gap.
The single workflow was fully analyzed with no dangerous audit findings or untrusted checkout paths. Its one action use is unpinned, which is a minor reproducibility concern, while the absence of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
thelia/installer Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.