Its 20 runtime dependencies create a broad update and compatibility burden, while the repository has no security scanning or policy. The stable version, matching repository, MIT declaration, and organization backing provide useful context.
55%
Total Score
75
50
88
83
Twenty runtime dependencies, including many Drupal Commerce modules and related packages, create a substantial compatibility and update burden for consumers.
The package has 36 releases since January 2024, but none in the last 12 months and the latest was published in March 2025, indicating a meaningful maintenance gap.
There were no commits and no active maintainers in the last three months, reinforcing the evidence that development has stalled.
Composer is used for the build, but no security scanning tools are configured, leaving dependency and repository changes with less automated oversight.
The repository has no security policy, making vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
drupal/select2 Version ^1.15 | — | — |
drupal/webform Version ^6.1 | — | — |
drupal/commerce Version ^2.36 | — | — |
drupal/rating_app Version ^1.0.2 | — | — |
drupal/commerce_stock Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.