Its README, release notes, and matching repository make the package easy to identify. The single maintainer and absent security policy provide little support if problems arise.
42%
Total Score
33
83
75
The latest release was published in October 2018, with no releases in the past 12 months. This long period without updates is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the past 3 months, consistent with the stale release history and leaving little evidence of ongoing maintenance.
Only one registry maintainer is listed. That is a limited contributor base and increases continuity risk, with no stronger organizational backing shown by the project context.
There were no new or closed issues or pull requests in the past month. With no recent commits or releases, this suggests inactivity rather than a demonstrably stable maintenance process.
The linked repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is secondary to the much older maintenance inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ~3.2 || ~4.1 | — | — |
contao-community-alliance/composer-plugin Version ~2.4 || ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.