The stable version format and Composer build setup are clear, but the package has had no release or commit activity for years and lacks a security policy. Choose an actively maintained alternative rather than adding this abandoned dependency.
12%
Total Score
50
30
83
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning against taking a new dependency on it.
The latest release was published in April 2018, and there have been no releases in over eight years. The 39-release history shows prior activity but does not offset the prolonged silence.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with its archived status and indicating no current maintenance capacity.
The linked repository is archived and was last pushed in July 2020, so it is no longer an actively maintained source.
Composer is used for the build, which supports reproducible package management, but no security-scanning tooling was detected. This is a minor transparency and maintenance gap alongside the stronger abandonment signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
drupal/redirect Version ^1.0@beta | — | — |
drupal/node_clone Version 1.x-dev | — | — |
drupal/paragraphs Version ^1.1 | — | — |
nrel/communications Version 3.0.4.1 | — | — |
drupal/config_update Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.