Package Health

theme-ultimate/installer-theme-ultimate

Usable with caveats: it is actively released and maintained, but this is a very small installer stub with a proprietary license and a repository that does not identify or document the package itself. Verify the licensing and repository relationship before adopting it.

Latest 4.4.2PackagistPackagist

64%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Dependency profilecaution

The installer declares three runtime dependencies, including a private repository-license package and the Theme Ultimate package itself. That is coherent for an installer, but the private licensing dependency creates an adoption prerequisite and increases dependency-chain complexity.

Licensecaution

The manifest declares a proprietary license, and no license file is included in the package or repository. This is explicit licensing rather than an unlicensed release, but it limits transparency and reuse for an open-source dependency.

Package file treecaution

The artifact and repository each contain only README.md and composer.json, consistent with the stated installer-stub role. This keeps the package easy to inspect but provides little implementation evidence of its own.

Repo bus factorcaution

One contributor made 21 of 22 recent commits, or about 95%, while a second contributor made one. Because the repository owner is recorded as a user rather than an organization, this concentration is a meaningful maintenance risk.

Repo package mentioncaution

The repository name does not match the package name, and its README does not mention this package. That raises a concrete concern that the package may be associated with the wrong or unrelated source repository.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Agentur Zentral GmbH

Direct Dependencies

DependencyLast ReleaseScore
oveleon/contao-cookiebar
Version ^2.3.6
—
—
theme-ultimate/theme-ultimate
Version 4.4.2
—
—
theme-ultimate/repository-license
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
29 days ago
Created
7 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform