Package Health

contao/core

The package is licensed and its artifact includes a README and changelog. Organization backing and the clean install profile do not offset the maintenance risk of relying on this release.

Latest 3.5.40PackagistPackagist

18%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

60

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Are you affected? Scan for Free

Health Score Breakdown

Package scaffoldingdanger

The artifact includes a README and changelog, but the README explicitly states that Contao 3.5 receives only security fixes and reached end of life in May 2019. The lack of published tests is normal packaging practice.

Release historydanger

The last release was published in April 2019, with no releases in the past 12 months; this indicates prolonged abandonment for a dependency release.

Repo commit activitydanger

The linked repository recorded zero commits and zero active maintainers in the past 3 months, providing no evidence of ongoing maintenance.

Security policycaution

The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This compounds the concern for an already unsupported release.

Vulnerabilities

TitleVersionsSeverity
CVE-2018-5478
contao/core is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 3.0.0 - 3.5.32.
3.0.0 - 3.5.32
Medium
CVE-2015-0269
contao/core is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 3.4.0 - 3.4.4 and 2.0.0 - 3.2.19.
2.0.0 - 3.2.193.4.0 - 3.4.4
Medium
CVE-2012-4383
contao/core is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 2.11.4.
0.0.0 - 2.11.4
High

Package versions

Maintainers

Leo Feyer

Direct Dependencies

DependencyLast ReleaseScore
leafo/scssphp
Version ~0.1
—
—
true/punycode
Version ~1.0
—
—
phpspec/php-diff
Version ~1.0
—
—
oyejorge/less.php
Version ~1.7
—
—
tecnick.com/tcpdf
Version ~6.0
—
—

Weekly Downloads

Info

Last Published
7 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform