The Acquia organization still owns the matching repository, which has a security policy and a clear consumer README. Composer tooling is present, but no repository security scanning is reported and recent commit activity is absent.
58%
Total Score
50
50
81
100
The package has 64 releases with a historically regular median interval of about 11 days, but it has had no releases in nearly four years. That long release gap materially raises abandonment and compatibility risk.
There were zero commits and zero active maintainers in the three months measured. This is the strongest repository-side maintenance concern and reinforces the stale release history.
Eight runtime dependencies, including Drupal core and migration components, make this a meaningfully coupled module but not an unusually large dependency surface for its stated function.
The repository uses Composer, which supports reproducible dependency handling, but no security scanning tools are reported. That is a modest transparency and maintenance gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/uri Version ^6.3 | — | — |
drupal/core Version ^9.0.6 | — | — |
drupal/migmag Version ^1.3 | — | — |
composer/semver Version ^3.0 | — | — |
drupal/migrate_plus Version ^5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.