The source repository remains available and backed by an organization, with a release note for this version. However, the package has no releases for nearly seven years and the registry directs users to a replacement.
18%
Total Score
100
57
83
The package is explicitly abandoned on Packagist at package scope, with govau/dta-uikit-base named as its replacement. This is a severe adoption warning despite the repository remaining available.
The last registry release was in November 2019, with no releases in the past 12 months; nearly seven years without a release indicates substantial abandonment risk for a Drupal theme.
The linked repository name does not match the package and its README does not mention the package, leaving uncertainty about whether it is the correct source rather than a repository used by a related package.
Composer is used as a build tool, but no security scanning tooling is present. This is a modest transparency gap, not a primary reason to reject the release.
The linked repository has no security policy, reducing disclosure transparency, although this is secondary to the package's deprecation and age.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.