The package has clear documentation and a small dependency surface, but it offers little current maintenance visibility. Its project is archived and has had no releases or commits for about two years, so pinning it creates substantial abandonment risk.
15%
Total Score
0
100
50
75
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on the package.
Although the package has 23 releases and historically released every few days, it has had no release in about two years. That recent inactivity is a strong maintenance concern.
The repository recorded zero commits and zero active maintainers in the last three months. Together with the archived status, this provides no evidence of ongoing development.
The linked repository is archived, which indicates the project is no longer expected to receive normal maintenance. Its last push was about two years ago, reinforcing the abandonment concern.
Composer is used for builds, but no security scanning tooling was detected. The missing scanning is a hygiene gap, though it is secondary to the archived and abandoned project state.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/default_content Version ^2.0.0-alpha1 | — | — |
cweagans/composer-patches Version ^1.7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.