Framework-free engine behind Droost: QA verify loop, AI-harness installers, skill emitters, scaffold blueprints, OKF wiki core, and code search/graph core for Drupal projects.
76%
Total Score
healthy
Healthy: 71 commits in three months, two active maintainers, and 26 releases in 49 days show active ownership.
The package declares GPL-2.0-or-later, but the detected artifact license is GPL-2.0; the mismatch should be clarified even though both the artifact and repository contain license files.
Twenty-six releases in 49 days show active development, though the very young package and rapid cadence provide limited long-term stability evidence.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest verification gap.
The repository has no security policy, which reduces transparency about vulnerability reporting and response expectations.
Version 0.7.9 is not a prerelease and recent releases are consistently stable versions, but the pre-1.0 major version signals an API that may still change.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
symfony/yaml Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/process Version ^6.4 || ^7.0 | — | — |
nikic/php-parser Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.