Its large dependency footprint increases maintenance burden, and an install-time script adds complexity. Tests, a license, and a matching source repository provide useful baseline transparency, but no security policy is present.
38%
Total Score
25
50
80
50
The package is nearly 10 years old, has had no release in that period, and has no releases in the last 12 months. This is strong evidence of abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap and providing no evidence of current maintenance.
The package declares 167 runtime dependencies and no development dependencies, creating a substantial maintenance and compatibility burden for a package that is no longer actively released.
A post-install-cmd script runs during installation, adding execution complexity and another maintenance surface. No provided signal compensates for that additional lifecycle behavior.
Only one registry maintainer is listed, and project_backing identifies the repository owner as an individual rather than an organization. That leaves a thin apparent support base.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
drupal/ds Version ^2.14 | — | — |
drupal/og Version ^2.9 | — | — |
drupal/bean Version ^1.11 | — | — |
drupal/date Version ^2.9 | — | — |
drupal/diff Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.