Usable with caveats: it is actively released, licensed, non-deprecated, and backed by an organization, but all recent commits come from one contributor and the repository does not identify this package in its README. The missing security policy and workflow permission declaration add transparency concerns.
65%
Total Score
88
100
83
75
One contributor made all 5 commits in the last 3 months, creating a real continuity risk. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository name does not match the package name and its README does not mention the package, so the linkage is not transparent and the package may be attached to a repository that does not clearly identify it.
The repository has 9 forks and 3 watchers but no stars, indicating limited visible adoption. This is supporting evidence only and does not outweigh the current releases and organizational backing.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency gap rather than evidence that the package is unsafe.
The repository has no SECURITY.md or other security policy, leaving vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
thelia/installer Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.