Its dependency footprint is minimal, installation has no lifecycle scripts, and the project is backed by an organization. The license text conflicts with the declared license, while testing, security policy, and workflow pinning remain limited.
72%
Total Score
67
100
79
50
The artifact contains a recognized GPL-3.0 license file, but the manifest declares LGPL-3.0+, so consumers should resolve the licensing mismatch before adoption.
The package has no README, tests, or changelog, but it does have a GitHub release for this exact version and the repository uses GitHub releases. The missing package tests and changelog are normal for published artifacts.
One contributor made 100% of the single recent commit, leaving no demonstrated second contributor to share maintenance. Organizational ownership provides some handoff capacity but does not remove the current concentration risk.
Only one commit was recorded in the last three months, showing limited recent development activity despite the recent release. This is a maintenance concern, but not evidence of abandonment by itself.
Composer is used for builds, but no security scanning tool is configured. This weakens automated supply-chain and dependency hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
thelia/installer Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.