Clear documentation and a licensed, substantial artifact make integration easier. The workflow findings are hygiene concerns, but recent activity and multiple contributors reduce abandonment risk.
78%
Total Score
100
86
50
The project uses Make and Composer for builds, but no security-scanning tools were detected, leaving less automated coverage for dependency or code security checks.
The repository has no security policy, leaving vulnerability reporting and response expectations less transparent. This is a documentation gap, not evidence of abandonment.
The release is not marked prerelease, but is_stable_major is false and the version format is nonstandard, which makes compatibility expectations less clear despite the active release history.
Both workflows use unpinned actions, and the release workflow has six high-confidence template-injection findings. No untrusted checkout or script-injection sink was reported, so these remain workflow hygiene concerns rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/core Version ^10 | — | — |
drupal/stable Version ^2.0 | — | — |
drupal/smart_trim Version ^2 | — | — |
drupal/ui_patterns Version ^1.5 | — | — |
drupal/twig_field_value Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.