Stable versioning, a clear README, a changelog, and an organization-backed repository provide useful maintenance context. The lack of recent commits and security scanning makes this an aging dependency rather than a strong default choice.
58%
Total Score
75
83
50
The package has 11 releases over roughly 12 years, but no releases in the last 12 months; the latest release was published in April 2019, indicating sustained release inactivity.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with a project whose development has effectively stopped.
The repository has zero stars and zero forks, with one watcher; this provides little supporting evidence of community adoption, but popularity alone is not decisive.
Composer is used for builds, but no security scanning tools are configured, leaving a modest transparency and maintenance-hygiene gap.
The repository has no security policy, which makes vulnerability reporting and response expectations unclear; this is a hygiene concern rather than evidence of a security defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ^3.5 || ~4.2 | — | — |
contao-community-alliance/composer-plugin Version ~2.4 || ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.