Usable with caveats: it is clearly published and documented, but maintenance appears to have stopped, with no release in about two and a half years and no recent repository activity. The small user footprint and absence of security tooling add uncertainty for a production dependency.
58%
Total Score
50
100
72
88
There were no commits and no active maintainers in the last three months. Combined with the old latest release, this is the main maintenance concern.
The package has 14 releases, but none in the last 12 months; its latest release was about two and a half years ago. That materially raises abandonment and compatibility risk.
There are no open issues or pull requests and no recent issue or pull-request activity. This is neutral rather than evidence of active maintenance because it may also reflect a very small user base.
The repository has only 1 star and no forks, indicating a very small visible adoption footprint. Popularity is supporting evidence rather than a verdict, but this reduces confidence in long-term community support.
Composer build tooling is present, but no security-scanning tools are reported. That is a transparency gap for supply-chain upkeep, though it is not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ^4.9 | — | — |
symfony/http-kernel Version ^4.4 || ^5.0 | — | — |
isotope/isotope-core Version ^2.8 | — | — |
symfony/translation-contracts Version ^1.0 || ^2.0 || ^3.0 | — | — |
heimrichhannot/contao-utils-bundle Version ^2.200 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.