The package is a small, clearly documented module with a stable version and matching source repository. Its maintenance and adoption risk are substantial, so use the listed replacement instead.
15%
Total Score
100
63
75
Packagist marks the entire package as abandoned and names heimrichhannot/contao-replace-bundle as its replacement. This is a direct indication that new projects should not depend on this package.
The latest release was published in December 2015, with no releases in the last 12 months despite the package being more than 11 years old. That strongly indicates the release line is no longer maintained.
Composer is used for builds, which is appropriate, but no security-scanning tooling is present. This is a modest hygiene gap rather than evidence of an unsafe release by itself.
The repository is not formally archived, but its last push was also in December 2015. The non-archived status does not offset the long period without source activity.
The linked repository has no security policy. For this small, old package this is a transparency gap, though the abandonment and explicit replacement are the more important concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core Version >=3.0,<4-dev | — | — |
menatwork/contao-multicolumnwizard Version >=2.10,<4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.