Eight active contributors, tests, and recent issue and pull-request activity provide useful continuity. The alpha status, long historical release intervals, missing security policy, and unpinned workflow actions warrant extra caution for production adoption.
76%
Total Score
100
83
50
The package has only four releases over about three years, with a median interval of roughly 351 days; two releases in the last 12 months and substantial repository activity partly offset the slow historical cadence.
The linked repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
This is an alpha prerelease, and all recent releases are prereleases, so compatibility and behavior may still change even though the major version is established.
All 17 workflows use read-only permissions and the audit found no injection or high-severity findings, but all 34 analyzed action references are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
drupal/core Version ^10.5 | ^11.2 | — | — |
drupal/field_group Version ^3.6 | ^4.0 | — | — |
drupal/field_group_table Version 1.x-dev@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.