The organization-backed repository has a clear README and the package includes an explicit license. Its broad dependency set and install-time scripts add upkeep and deployment complexity for adopters.
18%
Total Score
50
50
69
50
There is only one release, first and latest published in June 2017, with no releases in the last 12 months. That history is strong evidence of an abandoned release line.
The repository recorded zero commits and zero active maintainers in the last three months, while its last push was in 2017. This is the strongest evidence that the release is no longer maintained.
The template declares 43 runtime dependencies, including many Drupal modules and integration components. This creates a large maintenance and compatibility surface for a release that has not been updated.
The package defines six Composer install and update lifecycle scripts, so installation and dependency changes execute project code. This adds operational complexity and warrants caution even though the signal does not show malicious behavior.
One registry account has publish access, which is not by itself concerning because the project is backed by an organization. It provides limited publishing redundancy but does not offset the inactive release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
drupal/cdn Version 3.x-dev | — | — |
drupal/php Version 1.x-dev | — | — |
drupal/core Version 8.4.x-dev | — | — |
drupal/devel Version 1.x-dev | — | — |
drupal/token Version 1.x-dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.