It has a clear README, a matching organization-backed source tree, and no install-time scripts. The proprietary license is declared, but no security policy or automated security scanning is visible.
62%
Total Score
75
100
71
75
The package has eight releases since May 2019, but none in the last 12 months; the latest release was published on June 11, 2025. This indicates a real maintenance slowdown for a package used in an active CMS ecosystem.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the stalled release history. This raises abandonment risk despite the repository remaining available.
The repository has 12 stars and no forks, indicating limited external adoption and a small visible community. Low popularity is supporting evidence only, but it provides little independent resilience if maintainers stop responding.
Composer is used for build and dependency management, which fits the package ecosystem. No security scanning tooling is configured, leaving automated detection coverage limited.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency and maintenance gap, though not a severe risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ^4.13 || ^5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.