The repository is clearly tied to the package, and organizational backing plus release notes provide useful transparency. Resolve the license mismatch before adoption; the project also lacks a security policy.
68%
Total Score
100
100
81
83
The artifact contains a license, but it identifies GPL-3.0 while the manifest declares GPL-2.0-or-later. This mismatch should be resolved because it creates legal uncertainty for consumers.
Five releases were published on the same day, so the package has not yet demonstrated a sustained maintenance record. The recent release activity is encouraging but does not establish long-term stability.
Composer is used for build or dependency management, showing basic project tooling. No security scanning tools were detected, leaving a modest process gap.
The repository has no security policy. For a package intended to be integrated into a Drupal project, this is a transparency gap, although it is not evidence of a security defect by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.