The MIT license, matching repository, and organization backing improve transparency. Its dependency set is sizable, and no security policy or automated security scanning is present. Recent maintenance is also unconfirmed.
54%
Total Score
75
50
80
50
The package declares 12 runtime dependencies and no development dependencies. This is a substantial integration and update surface for a Drupal package, increasing upkeep risk.
The artifact has no README, while the absence of tests and a changelog is normal for published package contents. Missing consumer documentation is a modest transparency gap for a Drupal profile.
The package made six releases in roughly three months, but its latest release was in May 2025 and it has had no releases in the last 12 months. That pause lowers confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. The non-archived repository and organization ownership provide some continuity, but do not show current development.
The linked repository has no security policy. Its repository tooling also reports no security-scanning tools, leaving vulnerability reporting and automated checking less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
habeuk/vixcon Version ^1.1 | — | — |
drupal/metatag Version ^2.1 | — | — |
habeuk/hbk_popin Version ^1.0 | — | — |
drupal/search_api Version ^1.38 | — | — |
habeuk/hot_models Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.