The README provides clear setup and usage guidance for its local-development purpose, while the artifact includes a license and locked dependencies. Its narrow scaffold role limits the impact of several missing ecosystem features.
45%
Total Score
25
100
81
75
The package has only two releases, with no release in the last 12 months and the latest published in October 2022. That long release gap is a substantial maintenance concern, although the package is not deprecated.
The repository recorded no commits and no active maintainers during the last three months, consistent with activity having stopped nearly four years ago. This is the strongest abandonment signal in the assessment.
The repository is owned by a personal user account rather than an organization, so there is no demonstrated organizational backing to compensate for the thin maintenance evidence.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and maintenance gap, though it is secondary to the stale release and commit history.
The repository has no security policy. For a development scaffold this is a meaningful transparency gap, but it is not as serious as the evidence of prolonged inactivity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/core Version ^10.1 | — | — |
drush/drush Version ^11.2.1@rc | — | — |
drupal/redis Version 1.x-dev | — | — |
composer/installers Version ^2 | — | — |
drupal/admin_toolbar Version ^3.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.