Usable with caveats: the release is well documented, tested, licensed, and clearly backed by its matching repository, but it has had no release or commit activity for nearly four years. Depend on it only if its older Contao and PHP requirements still fit your project.
58%
Total Score
75
81
83
The package has seven releases since 2017, but none in the last four years; the latest release was published in October 2022. This materially increases the risk that compatibility and maintenance have stalled.
There were no commits and no active maintainers in the last three months, despite the repository being available. Combined with the old latest release, this is the main abandonment risk.
Composer is used as a build tool, but no security scanning tools are present. This is a transparency and assurance gap, though it is less serious than the prolonged inactivity.
The linked repository is not archived, but its last push was in October 2022. The unarchived status is positive, while the old last-push date is consistent with the maintenance concern from the release and commit signals.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This lowers transparency but does not by itself make the package unfit to use.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^1.38 || ^2.7 || ^3.0 | — | — |
contao/core-bundle Version ^4.9 | — | — |
contao/news-bundle Version ^4.9 | — | — |
symfony/translation-contracts Version ^1.0 || ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.