The matching repository, README, and release notes provide useful context. No license is declared or detected, while install/update scripts add operational surface; organization backing and stable versioning are modest positives.
42%
Total Score
50
100
75
67
The latest registry release was about 9 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk despite three historical releases.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Combined with the old registry release, this indicates the project is not receiving current maintenance.
No declared license, license file, or detected repository license was found. That leaves the release without clear permission for downstream use.
The package defines pre- and post-install/update Composer scripts. These are plausible for a Drupal install profile, but they increase installation complexity and execution surface.
Composer build tooling is present, showing a defined build mechanism, but no security scanning tools are reported. The tooling evidence is mixed rather than a decisive health concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
drupal/core Version ~8.0 | — | — |
drush/drush Version ~8.0 | — | — |
drupal/restui Version ^1.15 | — | — |
drupal/console Version ~1.0 | — | — |
drupal/openapi Version ^1.0@alpha | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.