Maintenance remains active, with two contributors and recent repository activity, while licensing and release documentation are clear. The absent security policy and no automated security scanning leave transparency and oversight gaps.
45%
Total Score
100
50
78
83
The package is marked as borrowing the identity of palantirnet/drupal-rector, with no self-described fork explanation; this is a serious dependency-confusion concern despite zero artifact overlap.
Thirteen runtime dependencies create a relatively broad dependency surface for a build-tool package, increasing ongoing update and compatibility burden.
The package has 65 releases since 2017, but none in the last 12 months; recent repository activity partly offsets the slower registry cadence.
Composer and Phing build tooling are present, but no security-scanning tools were detected, leaving a modest oversight gap.
The repository has no security policy, so it provides no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
drush/drush Version ^13 | — | — |
phing/phing Version ^2.14 | — | — |
phpmd/phpmd Version ^2.13 | — | — |
drupal/coder Version ^8.3.6 | — | — |
pear/http_request2 Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.