This is a healthy, well-structured release with an established history, a current stable version, active repository maintenance, organizational backing, tests, documentation, changelog coverage, and a clear license. The repository is not archived or deprecated, has three active maintainers and 37 commits in the last 3 months, and its CI workflow shows no analyzed dangerous patterns. The main reservations are the roughly 324-day median release interval, absent repository security policy, and unspecified top-level GitHub Actions token permissions; these are meaningful hygiene gaps but are outweighed by current development activity and strong package transparency.
86%
Total Score
100
100
88
70
The package uses post-install-cmd and post-update-cmd scripts, which increase installation-time behavior and warrant review when depending on the release. No provided signal shows these scripts are malicious or unsafe, so this is a caution rather than a severe risk.
The package has existed for about 4 years, with 6 releases and 2 releases in the last 12 months. The roughly 324-day median interval is slower than highly active projects, but the recent releases and repository activity indicate it is not abandoned.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanner is a hygiene gap, while the separate workflow analysis found no dangerous workflow patterns.
No SECURITY.md or equivalent security policy was detected, leaving vulnerability-reporting and response expectations less transparent. This is a maintenance and transparency gap, not evidence of an unsafe release by itself.
The sole workflow does not declare top-level token permissions, so its effective GitHub Actions token scope is less explicit than preferred. No workflow with explicit write permissions was detected, limiting the severity of this gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/core Version ^10 || ^11 | — | — |
drupal/multivalue_form_element Version ^1.0@beta | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.