This release appears reasonably safe to depend on from a maintenance and transparency perspective: it is actively released, non-deprecated, backed by a non-archived organization-owned repository, and includes substantial implementation code and tests. The main concerns are the proprietary manifest license without a license file, limited repository activity and popularity, concentration of recent commits in one contributor, and the absence of security scanning and a security policy. These issues warrant reviewing licensing and maintenance expectations before adoption, but the available evidence does not indicate abandonment or an otherwise unfit package.
78%
Total Score
100
100
83
90
The manifest declares a proprietary license and no license file was found, which creates a material licensing and transparency concern for a package presented as open source.
The repository has zero stars, forks, and watchers. This limits external validation and adoption evidence, although popularity is supporting evidence rather than a health verdict.
Composer build tooling is present, but no security-scanning tool was detected, leaving a security-process and maintenance-hygiene gap.
The repository has no security policy, reducing transparency about vulnerability reporting and coordinated response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
drupal/core Version ^10 || ^11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.