The repository is organization-backed, not archived, and the package includes tests with frequent releases. The source repository does not clearly identify this package, and it lacks a security policy and scanning.
22%
Total Score
75
100
69
75
Packagist marks the entire package as abandoned and names ueberbit/uebertool_companion as the replacement. This is a severe dependency risk even though the repository remains active.
The repository recorded no commits and no active maintainers in the last three months. This conflicts with the recent registry releases and raises concern about current development activity.
The repository name does not match the package name and its README does not mention the package. That makes package ownership and publishing provenance less clear, even though a name mismatch can occur with subtree packaging.
Composer build tooling is present, but no security scanning tools were found. That is a meaningful transparency and maintenance gap for a dependency package.
The repository has no security policy. This weakens the project's transparency for reporting and handling dependency issues.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/core Version ^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.