Open issues remain unresolved, and the project has no security policy or security-scanning tools. The package is clearly identified with its source repository and declares an LGPL-3.0+ license.
38%
Total Score
25
100
71
75
The latest release was published about 11 years ago, with no releases in the last 12 months. This is strong evidence of abandonment for a package still expected to support its ecosystem.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, and its last push was about 6 years ago. That leaves little evidence of ongoing maintenance.
The repository has 10 open issues and 7 open pull requests, with no new or closed issues or pull requests in the last month. Unresolved work reinforces the maintenance concern.
The repository has 1 star, 4 forks, and 5 watchers. Low popularity is only supporting evidence, but it provides little external maintenance signal for an already inactive project.
Composer is used for the build, which is appropriate, but no security-scanning tools are configured. That leaves a notable maintenance and vulnerability-detection gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core Version ~3.2 | — | — |
contao-community-alliance/composer-plugin Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.