The package includes tests, a security policy, and a substantial file tree, but its documentation warns that real Contao integration and migrations remain unverified. Workflow references are unpinned, reducing build reproducibility.
55%
Total Score
67
78
75
The manifest declares a proprietary license, with no recognized license text or license file. This may restrict adoption and is less transparent than a standard open-source license.
The artifact contains 181 files, documentation, application code, migrations, templates, and tests, indicating a substantial implementation rather than a minimal placeholder. The README still says integration and migration testing must be performed in a real Contao project.
The package and repository are owned by the same individual account, so the repository appears aligned with the package, but there is no organization backing shown.
The package is only 1 day old and has 15 releases, with a median interval of about 39 minutes. This shows active initial iteration but provides almost no evidence of sustained maintenance.
No commits or active maintainers were recorded in the last 3 months, while the repository was only recently pushed. This leaves sustained maintenance capacity unproven.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/uid Version ^6.4 || ^7.0 | — | — |
symfony/form Version ^6.4 || ^7.0 | — | — |
doctrine/dbal Version ^3.8 || ^4.0 | — | — |
symfony/mailer Version ^6.4 || ^7.0 | — | — |
symfony/validator Version ^6.4 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.