The package has a small, clear artifact, a stable version, a declared license, and no install-time scripts. It lacks tests and security tooling, leaving little evidence that the extension remains dependable as its ecosystem changes.
38%
Total Score
0
60
50
Only one release exists, and it was published in July 2018; there have been no releases in roughly eight years. This is strong evidence of abandonment for a package that integrates with a changing framework.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap. The repository is not archived, but there is no observed recent maintenance.
The repository has zero stars and one fork, providing little supporting evidence of adoption or community review. Popularity is only supporting evidence, so this reinforces the maintenance concern rather than determining it.
Composer is used for the build, which fits this PHP package, but the repository reports no security-scanning tooling. This is a modest transparency and maintenance gap rather than a standalone severe risk.
The linked repository has no security policy, so users have no documented vulnerability-reporting process. The package's small scope limits the significance, but the gap remains relevant for dependency maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ^4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.