The project includes tests, changelog, release notes, and a matching repository with organizational backing. Recent activity is concentrated in one contributor, and the workflow uses one unpinned action; these are manageable maintenance and build-hygiene concerns.
78%
Total Score
83
50
94
67
The release declares eight runtime dependencies, including Drupal core and related modules. This is a meaningful integration surface but remains plausible for the documented Drupal module.
Composer post-install and post-update scripts run during dependency operations. Such hooks add some supply-chain and installation complexity, although their presence alone does not show unsafe behavior.
All 3 recent commits came from one contributor, giving the repository a concentrated short-term bus factor. Organization backing partly offsets this, but succession risk remains.
Composer build tooling is present, but no security-scanning tools were detected. This is a transparency and hygiene gap rather than evidence of an unsafe release.
The repository has no security policy. That weakens vulnerability-reporting transparency for a module handling contact messages, although other project documentation and tests provide some compensation.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/core Version ^10 || ^11 | — | — |
drupal/rdf_skos Version ^1.3 | — | — |
drupal/contact_storage Version ^1.4 | — | — |
cweagans/composer-patches Version ^1.4 || ^2 | — | — |
drupal/contact_storage_export Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.