Package Health

acquia/drupal-cms-project

Active releases and recent repository work provide useful maintenance evidence. Organization backing, repository tests, security scanning, and a release note offset the workflow hygiene concerns and concentrated recent commits.

Latest 2.1.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo bus factorcaution

Recent work is concentrated in two contributors, with one responsible for 87.5% of the last three months' commits. Organization backing partly offsets this concentration, but it remains a maintenance-continuity concern.

Workflow auditcaution

All 14 analyzed action references are unpinned, and one workflow has top-level write permissions. A medium-confidence template-injection finding adds hygiene risk, although no untrusted checkout or script-injection path was found.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Acquia Engineering

Direct Dependencies

DependencyLast ReleaseScore
drupal/byte
Version ^1
—
—
drupal/webform
Version @beta
—
—
composer/composer
Version ^2.8
—
—
composer/installers
Version ^2.3
—
—
drupal/drupal_cms_ai
Version ^2
—
—

Weekly Downloads

Info

Last Published
7 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform