The release is well documented, licensed, correctly tied to its repository, and has no install-time scripts. Maintenance has stopped for about two and a half years, while the project has little visible adoption and no security policy or scanning.
55%
Total Score
50
100
83
88
There were no commits and no active maintainers in the last three months, consistent with the last push being about two and a half years ago. This materially raises abandonment risk.
The package has 33 releases since April 2019, but none in the last 12 months; its latest release was about two and a half years ago. This is meaningful evidence of slowing maintenance.
The repository has zero stars, one fork, and four watchers, indicating limited visible adoption. Popularity is supporting evidence rather than a standalone health verdict, so this is a modest concern.
Composer build tooling is present, but no security scanning tools are reported. That is a transparency and hygiene gap, not evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This lowers transparency for a package with framework and frontend dependencies.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0 || ^2.0 | — | — |
contao/core-bundle Version ^4.9 | — | — |
symfony/service-contracts Version ^1.0 || ^2.0 || ^3.0 | — | — |
symfony/dependency-injection Version ^4.4 || ^5.4 | — | — |
heimrichhannot/contao-utils-bundle Version ^2.196 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.