The package includes a README, changelog, stable version, and no install-time scripts. Its small user base and limited recent activity leave less evidence for long-term support, while repository security documentation is absent.
67%
Total Score
75
83
75
The package has existed for over 8 years with 20 releases, but only 1 release in the last 12 months; the latest release was about 11 months ago. This suggests limited current maintenance despite a substantial history.
There were 0 commits and 0 active maintainers in the last 3 months. Although the recent release shows some activity, the current contributor activity is too quiet to strongly support ongoing maintenance.
The repository has 1 star, 0 forks, and 5 watchers, indicating very limited visible adoption. Popularity is supporting evidence rather than a verdict, but it provides little external evidence of maturity.
Composer build tooling is present, but no security scanning tools were detected. This is a repository hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This weakens transparency for a package used in applications.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.9 || ^4.0 | — | — |
contao/core-bundle Version ^4.13 || ^5.0 | — | — |
symfony/dependency-injection Version ^5.4 || ^6.0 || ^7.0 | — | — |
heimrichhannot/contao-utils-bundle Version ^2.226 || ^3.0 | — | — |
symfony/event-dispatcher-contracts Version ^1.0 || ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.