Risky to adopt: this package has had only one release, with no new release in about 20 months and no linked source repository. Its minimal two-file artifact may fit a Drupal recipe, but the lack of consumer documentation and project transparency makes ongoing support difficult to judge.
42%
Total Score
50
70
75
There has been only one release, published about 20 months ago, with no releases in the last 12 months. That provides weak evidence of active maintenance and raises abandonment risk.
The package declares nine runtime dependencies and no development dependencies. This is a substantial dependency surface for a small two-file artifact, increasing reliance on external packages without visible repository evidence to assess compatibility or maintenance.
The artifact contains only composer.json and recipe.yml, consistent with a small Drupal recipe rather than a full library; however, the very limited contents provide little evidence about implementation quality, and no repository tree was available.
No README is present, which is a real usability gap for a package whose purpose and setup need to be understood; the absence of tests and a changelog is not concerning for a small published Drupal recipe, and repository scaffolding was not collected.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/zaya Version 1.0.x-dev@dev | — | — |
drupal/cookies Version ^1.2 | — | — |
drupal/profile Version 1.11 | — | — |
drupal/riddler Version ^3.0 | — | — |
drupal/mail_login Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.