Clear licensing, tests, and organization backing improve confidence. The package is small and well-scoped, but its early lifecycle leaves little evidence about long-term maintenance; pin this version while it proves its release cadence.
67%
Total Score
75
75
50
This is the first and only release, published less than a day ago, so there is no release history yet to demonstrate sustained maintenance or compatibility discipline.
The repository has no commits or active maintainers in the last three months, but the package and repository were created less than a day ago, so this is limited evidence rather than proof of abandonment.
Composer is used for the build, which fits the package ecosystem, but no security-scanning tooling is configured. That is a hygiene gap rather than a severe dependency risk.
The linked repository has no security policy, reducing transparency about vulnerability reporting and response expectations. The package's young age explains some of the missing project documentation but does not remove the gap.
Version 0.1.0 is an early major version, which signals that compatibility expectations may still be developing. It is not marked as a prerelease, providing a small compensating indication of intended release status.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/gin Version ^5.0 | — | — |
drupal/core Version ^11.2 | — | — |
drupal/gin_lb Version ^3.0@beta | — | — |
drupal/gin_toolbar Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.