Healthy and reasonable to adopt, with a few transparency caveats. It is actively maintained by an organization-backed repository with recent releases and matching source, but the project is only five days old and has no documented security policy or automated security scanning.
78%
Total Score
100
100
89
88
The package is only 5 days old with three releases, so it has limited track record despite a recent release every few days. This is a maturity caveat rather than abandonment evidence because repository activity is current.
Composer is used as the build tool, but no security scanning tools were detected. The missing scanning is a transparency and maintenance-process caveat, not evidence that the release is unsafe by itself.
No repository security policy was found. For a CMS project template, this leaves vulnerability-reporting practices undocumented and is a genuine transparency gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/og Version ^1.x-dev | — | — |
drupal/gin_lb Version ^3.0@beta | — | — |
mukurtu/mukurtu Version ^4.0 | — | — |
drupal/term_reference_change Version ^2.0@beta | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.