The template has a clear README, release notes, and organization backing. The license mismatch and absent security policy add transparency concerns, while the old project state makes ongoing support uncertain.
40%
Total Score
67
83
83
There were zero commits and zero active maintainers in the last three months, consistent with the last repository push occurring over five years ago. This is strong evidence that current support and fixes are unlikely.
The manifest declares GPL-2.0-or-later and the package contains a recognized MIT license file, with a repository license also present. The mismatch should be resolved before adoption because the applicable licensing terms are unclear.
The package has had no releases in the last 12 months, and its latest release was over five years ago despite having six releases historically. This is a substantial maintenance concern, although the repository is not archived.
Composer is used as a build tool, but no security scanning tools were detected. The missing scanning is a modest hygiene gap, not proof that the release is unsafe.
The repository has no security policy or documented reporting path. That weakens transparency and makes vulnerability coordination less clear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
drupal/shs Version ^1.0 | — | — |
drupal/smtp Version ^1.0 | — | — |
drush/drush Version ^10.3 | — | — |
drupal/devel Version ^4.0 | — | — |
drupal/redis Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.