The package includes a useful README, an MIT declaration, and a small dependency set. Its source has been inactive since October 2019, and the registry identifies a replacement package, so pinning this release would create avoidable maintenance risk.
18%
Total Score
25
100
64
88
Packagist marks the entire package as abandoned and names fiedsch/contao-jsonwidget as its replacement. This is a direct indication that new dependencies should not adopt this package.
The latest release was in January 2018, with no releases during the last 12 months. The seven-release history shows prior activity but does not offset the long period without a release.
There were no commits and no active maintainers in the last three months. Together with the old last push, this indicates sustained inactivity.
The package and repository are owned by the same individual account, so there is no mismatch in ownership context. Individual ownership does not provide the continuity of an organization-backed project.
Composer is used as a build tool, but no security scanning tooling is present. The missing scanning is a minor hygiene gap rather than the primary reason to avoid this release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ~2.7 || ~2.8 || ~3.2 || ~3.4 | — | — |
contao/core-bundle Version ~3.5 || ~4.4 | — | — |
symfony/expression-language Version ~2.7 || ~2.8 || ~3.2 || ~3.4 | — | — |
contao-community-alliance/composer-plugin Version ~2.4 || ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.