Organization backing, a matching repository, and a declared MIT license provide useful transparency. The repository has no security policy, so ongoing maintenance and security response remain unproven.
62%
Total Score
75
100
93
83
The package is 0 days old, with four releases published within about 6 minutes and a median interval of about 1.4 minutes. This shows active initial publishing but provides no established maintenance record.
The repository records zero commits and zero active maintainers over the last 3 months. Because the package is newly published, this mainly leaves long-term maintenance capacity unproven rather than demonstrating abandonment.
The linked repository has no security policy. That leaves vulnerability reporting and response expectations undocumented, a modest transparency gap for a package containing a substantial editor asset.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao-components/installer Version ^1.0.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.