The package includes a substantial README, automated tests, a clear license, and organization backing. Security scanning and a repository security policy are absent, leaving less protection as this new project develops.
62%
Total Score
83
100
89
88
This is the first release, published today, so there is no history showing sustained maintenance or release reliability yet.
The repository has no commits and no active maintainers recorded over the last three months; because the package is only one day old, this is an early-maintenance warning rather than evidence of abandonment.
Composer is used as the build tool, but no security-scanning tooling is configured, leaving a meaningful repository hygiene gap.
The repository has no published security policy, making vulnerability reporting and response expectations less transparent.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/key Version ^1.17 | — | — |
drupal/core Version ^10 || ^11 | — | — |
drupal/webform Version ^6.2 | — | — |
drupal/oauth2_client Version ^4.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.