The dependency set is broad for a project template, and the package offers little consumer documentation. Its declared GPL license and lack of install scripts are reassuring, but ongoing maintenance depth remains limited.
58%
Total Score
50
50
80
67
The template declares 41 runtime dependencies, creating a broad update and transitive-risk surface. That breadth is partly expected for a Drupal project template, but it still increases maintenance burden.
The published artifact and repository each contain only composer.json and composer.lock, leaving little visible project context for consumers to inspect. This is a transparency concern for a template intended to guide project setup.
No README, tests, or changelog are present, although missing tests and changelogs are normal for published artifacts and the release has a GitHub release marker. The absent README still makes integrating this project template harder.
This release is only 44 days old and is the package's sole release, so there is not yet enough history to demonstrate durable maintenance or compatibility practices.
All recent commit activity comes from a single contributor, with a 100% top-contributor share and no second active contributor shown. This leaves maintenance continuity dependent on one person.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/imce Version ^3.1 | — | — |
drush/drush Version ^13.7 | — | — |
drupal/blazy Version ^3.0 | — | — |
drupal/charts Version ^5.2 | — | — |
drupal/memcache Version ^2.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.