Documentation is minimal, and the repository has no security scanning or security policy. It is not deprecated or archived, while organization ownership provides some continuity.
36%
Total Score
50
50
63
75
The latest release was published in April 2021, and there were no releases in the last five years. That is strong evidence of abandonment risk despite a history of 19 releases.
The repository recorded zero commits and zero active maintainers in the last three months, indicating no observed ongoing development capacity.
The package declares 12 runtime Drupal dependencies and no development dependencies. This is a substantial dependency surface, increasing maintenance exposure, though it is plausible for a Drupal distribution profile.
The package includes a license file and repository license, but the manifest declares GPL-2.0+ while the detected text is GPL-3.0; that mismatch reduces clarity for adopters.
The package has a very short 46-character README, while absent tests and changelog are normal for a published Drupal artifact. The minimal consumer documentation remains a transparency gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/cdn Version ~3.0.0 | — | — |
drupal/core Version ~8.9.14 | — | — |
drupal/diff Version ~1.0.0 | — | — |
drupal/token Version ~1.1.0 | — | — |
drupal/ctools Version 3.0-alpha26 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.