Project template for Vactory.
38%
Total Score
0
75
50
The package has only two releases, with none in the last five years and the latest published in February 2021. This is strong evidence of abandonment risk despite the stable release format.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and limited ongoing maintenance capacity.
The package declares GPL-2.0-or-later and includes a license file, but artifact license detection also found MIT, Apache-2.0, and BSD-3-Clause text from bundled components. The mixed footprint warrants checking which license applies to the package and its included assets.
The package runs six Composer install and update lifecycle scripts, including pre- and post-install hooks. These increase installation complexity and the amount of package code executed during dependency operations.
The linked repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency gap for a project template with substantial bundled content.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
voidagency/vactory Version ^2.1 | — | — |
composer/installers Version ^1.2 | — | — |
drupal/core-recommended Version 8.9.13 | — | — |
voidagency/vactory_theme Version ^1.1 | — | — |
cweagans/composer-patches Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.