The release has clear installation guidance, release notes, and organization backing. Its short release history and absent recent commit activity leave maintenance capacity less proven than its packaging suggests.
64%
Total Score
75
88
50
Composer post-install and post-update scripts run during installation and updates. This is common for Drupal packages but increases install-time behavior that consumers should understand.
Only two releases have been published, with one release in the last 12 months and a median interval of about 206 days. This is a limited maintenance track record for a package intended as a project foundation.
There were zero commits and zero active maintainers in the last three months. Although the repository was pushed more recently overall, this recent inactivity weakens evidence of ongoing maintenance.
Composer build tooling is present, supporting a reproducible project workflow. No security scanning tools were detected, which is a modest transparency and maintenance gap.
The repository has no security policy. That leaves vulnerability reporting and maintainer response expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/core Version ^11 | — | — |
drupal/config_split Version ^2.0@beta | — | — |
drupal/config_rewrite Version ^1.4 | — | — |
drupal/symfony_mailer Version ^1.2 | — | — |
drupal/commerce_kickstart_base Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.