The package is clearly licensed, stable, and matched to an identifiable source repository. Security-process coverage is limited, and recent development activity is quiet despite the repository remaining unarchived.
65%
Total Score
50
100
88
75
The registry namespace and repository are both owned by the same individual account. A single-person project can be healthy, but it provides less organizational continuity than a backed project.
The package has existed since 2017 with nine releases, but it has had no release in the last 12 months; the latest release was over a year ago. This indicates slowing maintenance rather than clear abandonment.
There were zero commits and zero active maintainers in the last three months. With no release in the last 12 months, this is a genuine maintenance concern, though not proof of abandonment by itself.
The repository uses Composer for builds, but no security-scanning tools were detected. The missing scanning is a modest supply-chain hygiene gap, not a standalone adoption blocker.
The repository has no security policy. For a small extension this is a transparency gap, but it is less serious than an archived repository or demonstrated unmaintained dependencies.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^2.11 || ^3.0 || ^4.0 | — | — |
symfony/config Version ^5.4 || ^6.4 || ^7.3 | — | — |
contao/core-bundle Version ^4.13 || ^5.3 | — | — |
contao/news-bundle Version ^4.13 || ^5.3 | — | — |
symfony/http-kernel Version ^5.4 || ^6.4 || ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.