The organization-backed repository is unarchived, matches the package, and documents this release with concrete changes. A security policy and automated scanning help, but all three workflow actions are unpinned, leaving avoidable build-integrity exposure.
68%
Total Score
75
94
100
The package has 15 releases since 2018, but none in the last 12 months; its latest release was over two years ago. This is meaningful maintenance caution despite a historically established release record.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Combined with no registry releases in the last 12 months, this lowers confidence in active maintenance.
The sole workflow was fully analyzed with no untrusted checkout, script injection, or high-severity findings. However, all 3 action references are unpinned, which leaves the build exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
drupal/core Version >=10.0.0-alpha1 | — | — |
drupal/drupal-extension Version dev-main | — | — |
traviscarden/behat-table-comparison Version ^0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.