It has a clear README, stable dependencies, and no install scripts. Recent activity is limited to one contributor, and no security policy is provided.
55%
Total Score
50
100
79
75
The manifest declares a proprietary license, with no detected license text or license file. This creates a material adoption and redistribution constraint even though licensing is explicitly declared.
The registry namespace and repository are owned by the same individual account, not an organization. That is consistent ownership, but it provides no organizational handoff capacity.
The package has five releases over about two years, but none in the last 12 months; the latest release was about 14 months ago. This suggests slowing release maintenance, though the history is not abandoned-length.
All recent commits came from one contributor, giving the project a complete single-person bus factor. The matching repository and direct ownership help, but do not compensate for the concentration.
There was one commit in the last three months from one active maintainer. Recent activity is positive, but the very low volume provides limited evidence of sustained maintenance capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
drupal/core Version ^10.3 || ^11 | — | — |
jacerider/neo Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.