The package has a clear README, a matching organization-backed repository, and a declared GPL-2.0+ license. No security policy or scanning is reported, leaving maintenance and release hygiene less transparent.
60%
Total Score
75
100
88
50
Composer install, update, and create-project scripts are present, which is expected for a Drupal project template but means installation performs project-specific actions that should be understood by consumers.
The repository had zero commits and zero active maintainers during the last three months, a concrete sign of recently stalled maintenance despite its longer release history.
The repository uses Make and Composer for builds, but no security-scanning tools are reported, leaving an avoidable gap in project hygiene.
No repository security policy was found, reducing transparency about vulnerability reporting and response expectations.
The assessed version is 6.1.4 while the reported latest version is 5.4.5, an inconsistency that makes version provenance harder to interpret despite the stable-major and non-prerelease indicators.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupalwxt/wxt Version 6.1.x-dev | — | — |
composer/installers Version ^2.1 | — | — |
cweagans/composer-patches Version ^1.7 | — | — |
drupal/core-composer-scaffold Version 11.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.