Usable with caveats: this is a small, stable extension with a matching organization-backed repository, clear documentation, and no deprecation. However, it has had no registry release in the past year, no recent commits, and no security scanning or policy.
68%
Total Score
75
100
83
88
The package has existed since 2015 with five releases, but none in the last 12 months and a long median interval of about 794 days indicate slow maintenance. Its latest release was still published in May 2025, which partly offsets the concern.
There were no commits and no active maintainers in the last three months, a concrete sign that maintenance has currently slowed. The repository's October 2025 push provides some compensating evidence but does not demonstrate ongoing activity.
The repository has only one star and five forks, indicating a small user base. Popularity is supporting evidence rather than a requirement, so this lowers confidence in broad community scrutiny without making the package unsafe to adopt.
Composer is used for the build and packaging process, but no security scanning tool is configured. This is a transparency and assurance gap, though the package has no reported dangerous workflows.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a genuine transparency gap, but it is less severe for a small, stable extension than archival or deprecation would be.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ^4.13 | — | — |
contao-community-alliance/composer-plugin Version ^2.4.1 || ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.