Tests, a clear README, and active recent releases provide useful maintenance evidence. The small maintainer base and fully unpinned workflow actions leave avoidable continuity and build-integrity concerns.
68%
Total Score
50
100
100
50
One contributor made all 7 commits in the last 3 months, giving the project a bus factor of one. The repository is user-owned rather than organization-owned, so no provided backing signal compensates for that concentration.
Seven commits in the last 3 months show ongoing work, but all activity is concentrated in the same contributor identified by the repository signals. This supports current maintenance while leaving limited evidence of durable capacity.
The repository has no security policy, leaving no documented route for reporting vulnerabilities. This is a transparency gap for a CMS workflow module, though it is not evidence of an active security problem.
All 6 referenced actions are unpinned, which weakens build reproducibility and exposes CI to upstream action changes. The workflow has no dangerous trigger, injection, or write-permission finding, and the audit completed successfully, so this remains a hygiene caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ^5.7 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.