The repository matches the package, includes a license and README, and is owned by an organization. Its 16 runtime dependencies make compatibility upkeep a substantial concern for a Drupal project.
44%
Total Score
75
50
88
75
The package declares 16 runtime dependencies, including Drupal core and numerous modules, creating a substantial compatibility and upgrade burden for a release that has not been updated since 2019.
The package has made only one release, on March 30, 2019, with no releases in the past seven years. This is strong evidence of abandonment risk, although the package is not registry-deprecated.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the long release gap and materially increasing abandonment risk.
Composer is used for builds, but no security scanning tools are present. This is a modest transparency and maintenance-hygiene gap rather than evidence that the package is unsafe by itself.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. The organizational backing provides some context but does not replace a published process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
drupal/core Version ^8.0 | — | — |
drupal/chosen Version >=2.0 | — | — |
drupal/linkit Version >=5.0 | — | — |
drupal/pathauto Version >=1.0 | — | — |
drupal/redirect Version >=1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.