Package Health

alloy/alloy_blog

The package declares a proprietary license, and its Drupal module tree is substantial. There is no security policy or automated security scanning, while recent release activity has stopped.

Latest 2.1.1PackagistPackagist

66%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Package scaffoldingcaution

The package contains no README, tests, or changelog, which weakens consumer guidance and verification. Missing tests and changelog are normal for published package artifacts, but the missing README is a minor transparency gap for a Drupal module.

Release historycaution

The package has had seven releases since January 2023, but none in the last 12 months; this indicates a meaningful maintenance slowdown, partly offset by the repository being updated with the latest release.

Repo toolingcaution

Composer is used as the build tool, but no security-scanning tooling was detected. This is a modest supply-chain hygiene gap rather than evidence of abandonment.

Security policycaution

The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
1 year ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform