The phased, gated pipeline an agent runs to build or change a Drupal site: plan, code, test, document, complete. Framework-free — the Drupal surface ships with drupal/droost.
73%
Total Score
caution
Very active and well-documented, but still early-stage with a small maintainer base and incomplete security hygiene.
The package is only 53 days old but has 126 releases, with a median interval of about 2 hours 24 minutes. This shows strong activity but also reflects an unusually young and rapidly changing project.
Composer build tooling is present, but no security scanning tools were detected. That is a real transparency and maintenance gap, though it is not evidence of maliciousness by itself.
The repository has no security policy. This weakens the documented process for reporting and handling vulnerabilities.
Version 0.13.12 is not a prerelease, but the 0.x major version indicates the public API may still change before a stable release.
The single workflow was fully analyzed with no untrusted checkout or script-injection path, and its low-confidence cache-poisoning finding is hygiene rather than a demonstrated exploit. However, all 3 action references are unpinned, which reduces build reproducibility and supply-chain assurance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.4 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.