The package is clearly licensed, documented, and has a focused dependency set. Organization backing and a non-archived repository help, but limited security and maintenance evidence still warrant care.
58%
Total Score
100
100
86
75
This is the package's only release, published nearly 2 years and 10 months ago, with no releases in the last 12 months. That weakens confidence in ongoing maintenance despite the repository being updated later.
The linked repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a transparency gap, though it is partly offset by the repository's organization backing.
The sole workflow has a high-confidence template-injection finding and all 10 action uses are unpinned. It has no untrusted checkout or dangerous trigger, so these are material hygiene and supply-chain concerns rather than a critical risk on their own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/workbench Version ^1.4 | — | — |
drupal/workbench_access Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.