Risky to use: this Drupal site template appears effectively abandoned, with its only release published over seven years ago and no recent repository commits. The one-file package offers little transparency for a project with twelve runtime dependencies, despite having a declared license and no deprecation or install-time scripts.
32%
Total Score
0
50
75
50
Both the package and repository contain only composer.json. For a Drupal site template with twelve runtime dependencies, this provides very little source or documentation transparency.
This package has only one release, published over seven years ago, with no releases in the last 12 months. That strongly suggests it is no longer actively maintained.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the abandonment risk indicated by the one-release history.
The package declares twelve runtime dependencies, including Drupal, Drush, Composer plugins, and several related packages. This broad dependency surface increases maintenance exposure, especially alongside the lack of recent releases or commits.
The package has no README, tests, or changelog; missing tests and changelog are normal in published artifacts, but the absent README is a real usability and transparency gap for a site template. A GitHub release exists, but it has no release notes excerpt.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/core Version 8.6.6 | — | — |
drush/drush Version ^8.0 | — | — |
drupal/console Version ~1.0 | — | — |
npm-asset/blazy Version ~1.0 | — | — |
npm-asset/slick Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.