Active releases and recent repository work provide useful maintenance evidence. Organization backing, repository tests, security scanning, and a release note offset the workflow hygiene concerns and concentrated recent commits.
72%
Total Score
75
100
75
Recent work is concentrated in two contributors, with one responsible for 87.5% of the last three months' commits. Organization backing partly offsets this concentration, but it remains a maintenance-continuity concern.
All 14 analyzed action references are unpinned, and one workflow has top-level write permissions. A medium-confidence template-injection finding adds hygiene risk, although no untrusted checkout or script-injection path was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
drupal/byte Version ^1 | — | — |
drupal/webform Version @beta | — | — |
composer/composer Version ^2.8 | — | — |
composer/installers Version ^2.3 | — | — |
drupal/drupal_cms_ai Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.