The package lacks a security policy and consumer-facing README, while install-time scripts add operational complexity. Composer tooling and organizational ownership provide some context, but not enough to make this an attractive dependency.
15%
Total Score
50
42
50
There has been only one release, published in September 2017, with no releases in the last 12 months. The absence of subsequent releases strongly limits confidence that defects or compatibility issues will be addressed.
There are no open issues or pull requests and no recent issue or pull-request activity. In combination with the archived repository, this supports the conclusion that active maintenance is absent.
The linked repository is archived and was last pushed in April 2018, indicating the project is no longer maintained. This is a severe abandonment risk for a package intended to provide a Drupal project template.
The package runs post-install and post-update Composer scripts, which can change installation behavior and increase operational complexity. No provided signal shows those scripts are unsafe, so this is a moderate hygiene concern rather than a severe risk.
The package has no README, while tests and a changelog being absent are normal for a published project template. The missing README reduces transparency for consumers but is secondary to the maintenance concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cweagans/composer-patches Version ^1.6.0 | — | — |
drupal-composer/drupal-scaffold Version ^2.0.0 | — | — |
nrel/nrel_vendor_registration_profile Version ^1.002 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.