Usable with caveats: the package is licensed, clearly backed by its organization, and the repository matches the package. However, it has had no registry release in about 17 months and no commits in the last three months, so verify compatibility before adopting it.
58%
Total Score
83
100
83
90
Only three releases exist, all concentrated around April 2025, with no release in about 17 months. That is a meaningful sign of limited ongoing maintenance for a dependency intended to support evolving AI integrations.
There were zero commits and zero active maintainers in the last three months. Combined with the absence of registry releases for about 17 months, this raises a real maintenance and compatibility concern.
The repository has no stars or forks and only one watcher. This is weak supporting evidence, but popularity is not decisive for a small organization-backed recipe.
Composer build tooling is present, but no security scanning tools are configured. This is a transparency gap, though the repository has no workflows and is a small four-file recipe.
No security policy is provided. That limits reporting transparency, although the package is a small recipe with no workflow automation and this is not by itself evidence of unsafe maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/ai Version ^1 | — | — |
drupal/ai_provider_openai Version ^1 | — | — |
drupal/ai_provider_anthropic Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.