Package Health

ec-europa/oe_theme

Clear documentation, licensing, and regular project activity support continued maintenance. Workflow hygiene and the missing security policy leave additional trust gaps for a package that runs build and release automation.

Latest 5104.202501081505PackagistPackagist

67%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Registry deprecationdanger

The registry marks the package deprecated at package scope, with a replacement listed as the same package name. This is a meaningful adoption warning, although the active repository and recent releases show the project itself has not been abandoned.

Repo toolingcaution

The project uses Make and Composer for builds, but no security scanning tools were detected. The missing scanning layer is a modest transparency and maintenance concern.

Security policycaution

No repository security policy was found. For a maintained theme with build and release automation, this leaves vulnerability-reporting expectations unclear.

Workflow auditcaution

Both workflows use unpinned actions, and the release workflow has six high-confidence template-injection findings. Because no pull_request_target, workflow_run, untrusted checkout, or script-injection sink was reported, these remain workflow hygiene concerns rather than a standalone severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
drupal/core
Version ^10
—
—
drupal/stable
Version ^2.0
—
—
drupal/smart_trim
Version ^2
—
—
drupal/ui_patterns
Version ^1.5
—
—
drupal/twig_field_value
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform