Usable with caveats: this is a newly published package with only one release and one recent contributor, so long-term maintenance is unproven. It has a clear README, a stable release, an active organization-owned repository, and no install scripts or dangerous workflows.
68%
Total Score
67
100
88
90
The package is brand new: it has one release, published within the last day, and no established release history. That limits evidence of maturity and long-term maintenance.
All recent commits come from one contributor. The organization-owned repository provides some handoff capacity, but no second active contributor is shown in the supplied activity data.
There was one commit from one active maintainer during the last three months. Recent activity is positive, but the very limited volume provides little evidence of sustained maintenance.
Composer is used as a build tool, which fits the package ecosystem, but no security-scanning tooling is reported. This is a transparency and maintenance caveat rather than a severe risk.
No repository security policy is present. For a small, newly published package this reduces vulnerability-reporting transparency, though it does not by itself show abandonment.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/core Version ^11.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.