The package includes a README, changelog, release notes, and matching license files, while organization backing and a non-archived repository add useful continuity. The declared GPL-3.0-or-later license conflicts with the detected LGPL-3.0 file, and no security policy or scanning tools were found.
58%
Total Score
75
75
75
The artifact contains a license file and the repository also has one, but the manifest declares GPL-3.0-or-later while the detected file is LGPL-3.0. The mismatch warrants checking licensing before adoption.
Only two releases were published, with no releases in the last 12 months; the latest release was over 19 months ago. This indicates meaningful maintenance risk, though the package is still relatively small and may have a narrow scope.
The repository had no commits and no active maintainers in the last 3 months, reinforcing the long release gap and raising abandonment risk.
Composer build tooling is present, but no security-scanning tooling was detected. This is a modest transparency and maintenance-hygiene gap rather than a standalone adoption blocker.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear. This lowers transparency but does not by itself indicate that the release is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ^4.13 || ^5.0 | — | — |
symfony/http-kernel Version ^5.4 || ^6.0 | — | — |
contao/calendar-bundle Version ^4.13 || ^5.0 | — | — |
symfony/event-dispatcher Version ^5.4 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.