The repository is substantial and clearly matches the package, with organization backing and a modest dependency set. Its tiny README and absent security policy make ongoing maintenance harder to judge.
64%
Total Score
75
100
78
50
The artifact includes a LICENSE file, but it is detected as GPL-2.0 while the manifest declares GPL-2.0+, creating a concrete licensing inconsistency.
The package includes a README, but it is only 23 characters long and provides little consumer guidance. Missing tests and changelog files are normal for a published Drupal package and are not concerns here.
The repository had zero commits and zero active maintainers during the last three months. This is the strongest maintenance concern, though the recent registry release provides some compensating evidence.
The repository has zero stars, forks, and watchers, so there is little visible community adoption or independent attention. Organization backing and release activity partly offset this weak supporting signal.
Composer is used for the build, but no security scanning tools are configured, leaving automated security hygiene unconfirmed.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/field_group Version ^3.0 | ^4.0 | — | — |
novicell/entity_overview Version ^3.0 | — | — |
drupal/paragraphs_asymmetric_translation_widgets Version ^1.0@beta | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.