The package includes tests, release notes, a clear license, and organizational ownership. Maintenance has stopped for over four years, with no recent commits or releases, while all three workflow actions are unpinned.
55%
Total Score
75
83
50
The latest release was in July 2022, with no releases in the last 12 months; this is strong evidence of an aging package and raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and limited evidence of ongoing maintenance.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities, although this is a hygiene gap rather than evidence that the package is unsafe.
Both workflows were analyzed successfully with no dangerous triggers or audit findings, but all three action references are unpinned, leaving build inputs less reproducible and harder to trust over time.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/core Version ^8.8 || ^9.0 | — | — |
drupal/anchor_link Version ^2.2 | — | — |
composer/installers Version ^1.2 | — | — |
ckeditor-plugin/link Version ^4.14.0 | — | — |
su-sws/stanford_media Version ^8.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.