UT Drupal Kit site
68%
Total Score
caution
Usable with caveats: one-contributor maintenance and unpinned workflow actions weaken an otherwise active project.
One contributor made all seven commits in the last 3 months. Organization ownership provides some handoff capacity, but the lack of a second active contributor leaves maintenance continuity exposed.
Composer is used for builds, but no security scanning tools are reported. The missing scanning is a hygiene weakness, not evidence that the release is unsafe.
The repository has no security policy. That weakens vulnerability-reporting transparency for a project intended to be consumed as a dependency.
The sole workflow was fully analyzed with no high-confidence audit findings or untrusted checkouts, but all 4 of 4 action references are unpinned. This leaves workflow behavior exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
utexas/upstream-configuration Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.