This is a healthy, mature release with strong evidence of ongoing maintenance and transparency: it has been published for over 6 years, has 53 releases including 8 in the last 12 months, is a stable major release, and is backed by an active, non-archived organization-owned repository. The artifact includes substantial documentation, tests, a changelog, licensing, and a coherent 293-file source tree. The main reservations are the absence of repository security scanning and a security policy, unspecified GitHub Actions token permissions, and install/update lifecycle scripts; these are hygiene and supply-chain transparency gaps rather than evidence that the package is unfit to depend on.
88%
Total Score
100
100
94
70
The package defines post-install-cmd and post-update-cmd scripts, which require extra trust during dependency operations and add supply-chain exposure, although this is not by itself evidence of unsafe behavior.
Composer build tooling is present, but no security-scanning tools were detected; this is a genuine security-process gap, partially offset by the otherwise structured repository and CI workflow.
No repository security policy was found, leaving vulnerability-reporting expectations and response procedures undocumented.
The only workflow lacks top-level token permissions declarations. Although no top-level write permissions were observed, the absence of an explicit least-privilege policy reduces CI transparency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/core Version ^10 || ^11 | — | — |
drupal/facets Version ^2.0 | — | — |
drupal/search_api Version ^1.27 | — | — |
symfony/options-resolver Version ^6 | — | — |
drupal/entity_meta_relation Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.