The project has a clear license, release notes, and organization backing. Its small contributor footprint and absent security policy leave maintenance and disclosure practices less established.
64%
Total Score
83
100
79
75
The artifact includes a license file and the repository also has one, but the declared GPL-2.0-or-later differs from the detected GPL-2.0 text, creating a minor clarity concern.
All six releases were recorded today, so the registry history does not yet demonstrate a sustained release cadence or long-term maintenance.
The repository recorded zero commits and zero active maintainers in the past three months, which weakens evidence of ongoing maintenance despite the recent release.
Composer build tooling is present, but no security scanning tools were detected, leaving the project's automated security coverage unclear.
The repository has no security policy, so there is no documented path for reporting vulnerabilities or understanding its disclosure process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
drupal/core Version ^9 || ^10 | — | — |
drupal/workbench_email Version ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.