This is a healthy, established release with a clear license, complete package scaffolding, tests, changelog, a matching and actively updated organization-owned repository, and a sustained release history since 2020. Maintenance activity is current, although recent commits are concentrated in two contributors, and the repository lacks a security policy, security-scanning tooling, and explicit top-level GitHub Actions token permissions. These are meaningful hygiene gaps but are outweighed by the package's active development, organization backing, non-archived status, stable release, and strong artifact transparency.
86%
Total Score
88
94
70
The package uses post-install-cmd and post-update-cmd scripts. Lifecycle hooks deserve review because they execute during dependency operations, although this signal alone does not establish that the scripts are unsafe or undermine project health.
Recent activity involves two contributors, but the leading contributor accounts for 83.3% of commits. Organization backing provides some handoff capacity, yet the observed concentration remains a moderate continuity risk.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning layer is a repository hygiene gap, though it does not by itself indicate abandonment.
No repository security policy was found. This reduces transparency about vulnerability reporting and response procedures, creating a genuine but limited governance gap.
The sole workflow lacks top-level token permissions, and no read-only permissions declaration was detected. Explicit least-privilege configuration would improve CI security hygiene, although no top-level write permission was observed.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/core Version ^10 || ^11 | — | — |
drupal/rdf_skos Version ^1.3 | — | — |
drupal/multivalue_form_element Version ^1.0@beta | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.