This is a healthy, mature release with a strong maintenance and transparency profile: it has been published since 2019, has 58 releases including 10 in the last 12 months, is stable, non-deprecated, actively pushed, and supported by six active maintainers with balanced contribution shares. The artifact and repository include substantial documentation, changelog, tests, licensing, and a large coherent file tree, while the linked organization-owned repository clearly matches the package. The main reservations are lifecycle install/update scripts, the absence of a repository security policy and dedicated security scanning, and undeclared top-level GitHub Actions token permissions; these warrant review in a dependency-security process but do not outweigh the strong evidence of active maintenance and project backing.
88%
Total Score
100
100
94
70
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/core Version ^10.3 || ^11 | — | — |
php-http/guzzle7-adapter Version ^1.0 | — | — |
cweagans/composer-patches Version ^1.7 || ^2 | — | — |
jakeasmith/http_build_url Version ^1.0 | — | — |
drupal/backport_node_storage_body_field Version ^1 || ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.