Thyme Framework appears usable and reasonably transparent for an early-stage package: it has a clear MIT declaration, a substantial README, source tests, Composer-based tooling, active recent development, organization backing, and no deprecation or dangerous workflow findings. However, the release is only 11 days old with a single published version, commit activity is highly concentrated in one of two contributors, and repository security hygiene is incomplete because there is no security policy or security scanning and one workflow lacks top-level permissions. These concerns warrant caution for long-lived production dependencies, but the available evidence does not indicate abandonment or an otherwise unfit package.
72%
Total Score
80
100
83
80
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
roots/acorn Version ^6.2 | — | — |
vinkla/extended-acf Version ^15.1 | — | — |
automattic/jetpack-autoloader Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.