It includes a clear license, a substantial README, matching source files, and no install-time scripts. Recent repository activity is absent, while every workflow action is unpinned and the release workflow uses long-lived registry publishing credentials.
64%
Total Score
50
100
89
67
The repository recorded no commits and no active maintainers in the three months before collection. The recent release history provides some compensation, but this still raises a maintenance concern.
The repository has one star and no forks, indicating limited external adoption and review. Popularity is supporting evidence rather than a health verdict, so this is only a mild concern.
Composer build tooling is present, but no security scanning tooling was detected, leaving a modest transparency and hygiene gap.
The repository has no security policy, which makes vulnerability reporting and response expectations less clear.
The workflow audit completed fully and found no untrusted checkouts or script injection, but all three action uses are unpinned and the high-confidence use-trusted-publishing finding indicates long-lived registry credentials. These are workflow hygiene and supply-chain concerns, not evidence that the package is malicious.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
drupal/pathauto Version >=1.12 | — | — |
drupal/color_field Version >=3.0 | — | — |
drupal/focal_point Version >=2.1 | — | — |
drupal/easy_breadcrumb Version >=2.0 | — | — |
drupal/bootstrap_italia Version 2.17.x-dev@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.