Its small scope, single runtime dependency, and organization ownership limit complexity. However, the last release and repository update were in March 2018, with no recent issue or pull-request activity; pin this only when legacy compatibility is required.
43%
Total Score
75
100
79
50
The package has only two releases, with the latest published in March 2018 and none in the last 12 months. The roughly eight-year gap is strong evidence of abandonment risk.
There were no new issues, closed issues, pull requests, or merges in the last month. Combined with the old last release, this supports a conclusion of inactive maintenance.
Composer is used as the build tool, but no security-scanning tooling is present. For this small legacy package that is a hygiene gap rather than a severe dependency risk.
The repository has no security policy. This reduces transparency for reporting problems, although the package's narrow scope limits the impact of that gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core Version >=3.2,<4-dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.