The package is correctly linked, licensed, and documented with release notes. Its installation scripts, exposed default administrator credentials, and apparent database backup make the release harder to trust and maintain safely.
38%
Total Score
50
83
25
The published tree includes a var/backups/backup__20250827130030.sql file alongside website assets, which is poor release hygiene and may expose deployment data.
The package runs both post-install and post-update Composer scripts, adding installation-time behavior that consumers must inspect before adoption.
The package is about 17 months old with eight releases, but only one release in the last 12 months; the long recent gap suggests slowing maintenance.
The repository had zero commits and zero active maintainers in the last three months, providing no evidence of ongoing maintenance for this release.
Two issues remain open, while no issues or pull requests were created or closed in the last month, indicating limited recent project activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/intl-extra Version 3.20.* | — | — |
contao/conflicts Version *@dev | — | — |
contao/faq-bundle Version 5.6.* | — | — |
contao/core-bundle Version 5.6.* | — | — |
contao/news-bundle Version 5.6.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.