This is a healthy, mature release with strong evidence of active maintenance and transparent packaging: it has 297 releases over more than five years, 74 releases in the last 12 months, a stable major version, current repository activity, organization backing, tests, a changelog, a README, a license file, and a repository that clearly matches the package. The main cautions are install-time Composer lifecycle scripts, the absence of a security policy and security scanning, and workflow permissions that are not explicitly constrained; these are hygiene concerns rather than evidence of abandonment. Recent activity is concentrated in two contributors, but both remain active and the repository is organization-owned, which reduces bus-factor risk.
88%
Total Score
100
100
94
70
The package declares post-install-cmd and post-update-cmd Composer scripts. These may be normal for Composer-managed Drupal dependencies, but they increase install-time behavior and warrant review before adoption.
Composer build tooling is present, supporting reproducible project workflows, but no security scanning tools were detected; the missing scanning is a security-hygiene gap rather than evidence of poor maintenance.
No repository security policy was found. This reduces vulnerability-reporting transparency, although it is not by itself evidence that the package is unsafe or abandoned.
The release workflow lacks top-level token permissions declarations. Although no top-level write permissions were observed, explicitly constraining permissions would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/core Version ^10.6 || ^11 | — | — |
drupal/file_link Version ^2.2 | — | — |
drupal/ui_patterns Version ^1.10 | — | — |
cweagans/composer-patches Version ^1.7 | — | — |
openeuropa/ecl-twig-loader Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.