Allows CU Boulder site administrators to configure site-specific settings.
58%
Total Score
caution
Usable with caveats: no release since 2023 and workflow supply-chain hygiene needs attention.
The package has only four releases and none in the last 12 months; its latest registry release was in December 2023, indicating a real freshness concern for a Drupal module.
No commits or active maintainers were recorded in the last three months, which weakens evidence of ongoing maintenance despite the repository not being archived.
Composer build tooling is present, but no security-scanning tools were detected; this is a modest process gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented and reducing transparency for a package used in site administration.
All five workflows use unpinned actions, and a high-confidence medium-severity finding shows a reusable workflow inheriting secrets. No untrusted checkout or script injection was found, so this is a hygiene and credential-scope concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.