The repository has organization backing and clearly matches the package, but it remains small and lacks a security policy. Resolve the license mismatch before adoption.
55%
Total Score
75
83
75
The manifest declares GPL-2.0-or-later, while the artifact license file is identified as GPL-3.0. A license file exists, but the mismatch creates avoidable legal uncertainty.
There are four releases, all concentrated within about 5 days, and no later releases across the remaining package lifetime. This provides limited evidence of sustained maintenance.
The repository recorded no commits and no active maintainers during the last three months. For a package only about 5 months old, that suggests maintenance has stalled rather than demonstrating a stable long-term cadence.
The linked repository has no security policy. That weakens vulnerability-reporting transparency, although it is not evidence of a security incident by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
drush/drush Version ^13 | — | — |
composer/installers Version ^2.3 | — | — |
drupal/core-recommended Version ^11 | — | — |
cweagans/composer-patches Version ^2.0 | — | — |
drupal/core-recipe-unpack Version ^11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.