The module is clearly licensed, has a usable README, and keeps its dependency list small. Only six releases exist, all recent releases are beta, and no commits landed in three months, so ongoing maintenance is uncertain.
58%
Total Score
75
100
81
50
The package has six releases over about two and a half years, but it had no releases in the last 12 months. That is a meaningful maintenance concern despite the earlier roughly 19-day median interval.
There were no commits and no active maintainers in the last three months. The recent repository push partly offsets abandonment concerns, but the current pause still lowers confidence in ongoing maintenance.
Composer is used as the build tool, showing basic project tooling, but no security scanning tools were detected. For a small module this is a hygiene gap rather than a severe risk.
The repository has no security policy. That reduces transparency about vulnerability reporting and response, although it does not by itself show that the package is unsafe.
The assessed version is a prerelease, and all recent releases are prereleases. This signals that the package may not have reached a stable compatibility point.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
drupal/metatag Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.