A missing security policy, no automated security scanning, and one unpinned workflow action reduce transparency. The organization-backed repository is active, licensed, documented, and has a second recent contributor.
78%
Total Score
100
100
89
75
The repository has no stars and one fork, offering little adoption evidence; popularity is supporting evidence and does not outweigh the observed maintenance signals.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and assurance gap.
The repository has no security policy, so users lack a documented reporting path for vulnerabilities in a module that exposes signed HTTP triggers.
The single workflow was fully analyzed with no dangerous triggers, sinks, or audit findings. However, its one action is unpinned, which leaves a modest reproducibility and workflow supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/lock Version ^7.0 | — | — |
symfony/process Version ^7.0 | — | — |
thelia/installer Version ~1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.