The focused package has a README, an explicit LGPL license, and a small dependency surface. Organization ownership helps, but the absence of tests, security policy, and recent development reduces confidence in long-term support.
45%
Total Score
75
100
75
50
The package has had only three releases, with none in the last 8 years and a median interval of about 2 years, indicating substantial abandonment risk.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the long release gap and limited evidence of ongoing maintenance.
Composer is used for builds, but no security-scanning tooling is present; this is a modest transparency and maintenance gap rather than evidence of unsafe behavior.
The linked repository has no security policy, leaving vulnerability-reporting expectations unclear for a package intended to be used as a dependency.
The latest release is still marked 1.0-RC3, and all recent releases are prereleases, which weakens maturity expectations for a dependency this old.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao-community-alliance/dc-general Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.