Licensing is clear, and the package includes tests and a useful README. Its substantial dependency set increases the cost of taking over maintenance.
12%
Total Score
25
50
50
100
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct indication that relying on this release carries severe abandonment risk.
The latest release was published in July 2020, with no releases in nearly six years and no releases during the last 12 months. This strongly indicates the package is no longer maintained for current consumers.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the archived status, this provides no evidence of ongoing maintenance capacity.
The linked repository is archived, despite a last push in September 2024. An archived source project is generally no longer accepting normal maintenance and is a severe dependency risk.
The package declares 16 runtime dependencies, including Drupal, Drush, and Composer plugins. That breadth increases upgrade and takeover effort when the project is no longer maintained.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drush/drush Version ^8 | — | — |
composer/installers Version ^1.0 | — | — |
cweagans/composer-patches Version ^1.0 | — | — |
drupal/composer_autoloader Version 1.* | — | — |
drupal-composer/preserve-paths Version 0.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.