The project shows no active commit or issue work, and its own README says it was revived for a conference talk rather than production use. Licensing and package ownership are clear, but they do not offset the release's stated limitations.
20%
Total Score
75
69
83
The package includes a README, but it explicitly says this is a conference-talk revival, should not be used in production, and uses outdated JavaScript and deprecated markers. Missing tests and a changelog are normal packaging gaps and do not drive the score.
All 17 releases occurred within the same release burst on 24 September 2025, with a median interval of zero days; this shows packaging activity but not sustained maintenance.
The repository recorded zero commits and zero active maintainers during the last three months, indicating no current maintenance capacity for a package already labeled as an example.
Composer build tooling is present, but no security-scanning tools are reported. This is a modest hygiene gap rather than evidence of unsafe behavior.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, though it is secondary to the project's explicit production warning.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ^5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.