OS2Forms payment
60%
Total Score
caution
Usable with caveats: no registry release in about 19 months and no commits in the last 3 months.
The latest registry release was about 19 months ago, with no releases in the last 12 months. This is a meaningful maintenance concern despite the package having six releases overall.
There were no commits and no active maintainers in the last 3 months. This weakens confidence in ongoing maintenance, although the repository was pushed in March 2026.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanning is a hygiene concern for a payment-related module.
No repository security policy was found. For a module handling payment integration, this reduces transparency around vulnerability reporting and response.
The workflow was fully analyzed and has no untrusted checkout or script-injection findings, but all 13 action references are unpinned. The high-confidence template-injection finding is a workflow hygiene concern without a corroborating dangerous trigger or sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
drush/drush Version ^11 || ^12 | — | — |
drupal/webform Version ^6.1 | — | — |
drupal/advancedqueue Version ^1.0 | — | — |
symfony/options-resolver Version ^5.4 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.