The repository is unarchived and includes a clear README, license, and release workflow. Its workflow uses unpinned actions, and no security policy or scanning is present.
57%
Total Score
50
88
50
The package has 95 releases, but none in the last 12 months; its latest release was about 17 months ago. This suggests maintenance may have stalled despite its earlier release history.
The repository had zero commits and zero active maintainers in the last three months. Combined with no releases in the last year, this is meaningful evidence of currently stalled maintenance.
Composer is used for builds, but no security-scanning tool is configured. This is a transparency and maintenance weakness, though it does not by itself make the release unfit.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The single workflow was fully analyzed with no dangerous triggers or audit findings, and it scopes permissions at job level. However, both of its two action references are unpinned, leaving a modest reproducibility and workflow supply-chain gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ouitoulia/lexika Version >=3 | — | — |
drupal/migrate_file Version >=2.1 | — | — |
drupal/migrate_plus Version ^6 | — | — |
ouitoulia/themethla Version >=5 | — | — |
drupal/migrate_tools Version ^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.