This is a healthy, actively maintained release with a seven-year history, 46 releases, five releases in the last 12 months, and a stable non-prerelease version. The linked organization-owned repository is active, unarchived, correctly associated with the package, and shows recent work from two contributors; the artifact also includes documentation, tests, a changelog, a license file, and substantial project structure. The main reservations are the absence of a repository security policy and security-scanning tools, plus a CI workflow without explicitly declared top-level token permissions. These are meaningful transparency and workflow-hygiene gaps, but they do not outweigh the strong maintenance and packaging evidence.
88%
Total Score
100
100
94
70
The package defines post-install and post-update Composer scripts. These add install-time behavior that should be reviewed, although lifecycle scripts are common in Composer packages and no dangerous workflow behavior is reported.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning layer is a genuine supply-chain hygiene gap, though it is not evidence of maliciousness or abandonment by itself.
No repository security policy was found. This weakens vulnerability-reporting transparency, but the gap is moderate because the repository remains active and other project-health signals are strong.
The only workflow lacks top-level permissions declarations. Although no top-level write permissions were detected, explicit least-privilege permissions would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/core Version ^10 || ^11 | — | — |
cweagans/composer-patches Version ~1.4 || ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.