A tool for testing a company's software packages together in the context of a realistic, functioning, best practices Drupal build
68%
Total Score
75
50
94
83
The package declares 35 runtime dependencies, including Composer, Drupal analysis, Symfony, and testing-related components. That broad dependency surface raises update and compatibility burden, though it fits the package's role as an integration-testing tool.
post-install-cmd and post-update-cmd scripts run during dependency installation or updates. This is common for Composer tooling but increases installation complexity and the code executed during dependency operations.
The repository has 0 commits and 0 active maintainers in the last three months. Although a recent push and six releases in the last year provide some compensation, the current development activity is a meaningful maintenance concern.
Three pull requests were opened in the last month and none are reported as merged, while no new issues were opened. This shows some activity but limited completed work.
The assessed release is marked stable and not a prerelease, with no recent prerelease share. However, the reported latest registry version is older than the assessed v5.1.2, which creates a small transparency concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpmd/phpmd Version ^2.13 | — | — |
symfony/yaml Version ^6.3.0 | — | — |
ergebnis/json Version ^1.3.0 | — | — |
symfony/cache Version ^6.4.18 | — | — |
oscarotero/env Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.