The README, matching source repository, organization backing, stable version, and declared license improve transparency. Its focused artifact has no install-time scripts, but the project offers little evidence of current security or maintenance practice.
45%
Total Score
67
79
75
The latest release was in March 2016, with no releases in the last 12 months; roughly ten years without a release is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and limited evidence of ongoing maintenance.
There were no new or closed issues or pull requests in the last month, while two issues and one pull request remain open; this suggests little recent project activity.
Composer and Phing provide build tooling, but no security-scanning tools were detected, leaving a modest transparency and maintenance gap.
No repository security policy was found, leaving vulnerability-reporting expectations unclear for a package intended to run inside a CMS.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core Version >=2.11,<4 | — | — |
contao-community-alliance/contao-twig Version ~1.11 | — | — |
contao-community-alliance/composer-plugin Version ~2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.