The small codebase and simple dependency set limit integration risk. Documentation is brief and there is no stated security process, so ongoing support deserves attention.
65%
Total Score
50
100
89
83
The registry namespace and repository owner are the same individual account, so there is no observed organizational backing. The package's recent release provides some compensating evidence, but the support base remains narrow.
The package has existed for about 6 years and released once in the last 12 months, but its median release interval is about 19 months. The recent release is reassuring, though the long intervals suggest limited maintenance capacity.
No commits and no active maintainers were recorded in the last 3 months. The same-day latest push and recent release partly offset this, but the short-term inactivity still lowers confidence in ongoing maintenance.
No new or closed issues or pull requests were recorded in the last month, while there are no open pull requests. This shows little current community activity but no visible backlog signal.
Composer is used for the build, but no security scanning tool was detected. The missing scanner is a hygiene gap rather than evidence of an unsafe release on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ~4.13 || ~5.0 | — | — |
rapidmail/rapidmail-apiv3-client-php Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.