The package includes tests, a changelog, and a substantial README. Organization backing and a matching repository add continuity, while the license mismatch and workflow credential sharing need attention.
76%
Total Score
88
50
81
50
The package declares 22 runtime and 15 development dependencies, consistent with a substantial Drupal application. The breadth adds maintenance complexity but is not independently disqualifying.
The manifest declares the package proprietary, but the repository license file is detected as GPL-2.0; the release therefore has a material licensing inconsistency despite having a repository license.
One contributor made 75% of the 32 recent commits, but four other contributors were active and the repository is organization-owned. The concentration is a manageable continuity concern rather than a severe abandonment risk.
Composer is used for builds, but no security scanning tooling was detected. The missing scanning is a modest supply-chain hygiene gap, not evidence of unsafe behavior by itself.
The linked repository has no security policy, reducing transparency about vulnerability reporting and maintenance expectations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
dpc-sdp/bay Version ^0.0.1 | — | — |
drush/drush Version ^8.1 | — | — |
dpc-sdp/tide Version ^0.0.3 | — | — |
drupal/devel Version ^1.2 | — | — |
drupal/coffee Version ^1.0@beta | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.