The release is licensed, uses a stable version, and has no install-time scripts. Its repository lacks security scanning and a security policy, leaving oversight and ongoing support thin.
38%
Total Score
0
58
75
The package has had no releases in the last 12 months, and its latest release was nearly three years ago. Nine releases show some initial activity, but the prolonged publishing gap is a substantial abandonment concern.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.
A license file is present and the package declares GPL-2.0-or-later, but the artifact license file was detected as GPL-3.0. That mismatch creates legal uncertainty for adopters.
The repository name does not match the package name and its README does not mention the package. That weakens confidence that the linked source repository directly belongs to this release.
Composer build tooling is present, but no security scanning tools were detected. For a Drupal plugin shipping a large compiled asset tree, that is a real oversight gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
vshandak/aesirx_analytics_lib Version ^v1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.