The package has a clear README, changelog, stable versioning, and repository tests, with an organization-backed project and Dependabot enabled. No deprecation or archival concerns are present, but the limited popularity and absent security policy reduce confidence for long-term adoption.
68%
Total Score
75
50
94
83
The package declares 14 runtime dependencies across Contao, Symfony, Twig, and related libraries. This is a meaningful integration surface and adds maintenance exposure, but it is proportionate to a Contao bridge extension.
The repository recorded zero commits and zero active maintainers in the last three months. This suggests a current maintenance pause, although the recent registry release and June push partly offset abandonment concerns.
There are no open issues or pull requests and no activity in the last month. This is not harmful by itself for a small stable package, but it offers little evidence of active community support.
The repository has only 2 stars, 1 fork, and 2 watchers. Low popularity is supporting evidence rather than a health verdict, but it provides little external adoption evidence.
No security policy is present in the repository. This is a transparency gap for reporting and handling vulnerabilities, though it does not by itself indicate that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.8 | — | — |
doctrine/dbal Version ^3.9 || ^4.0 | — | — |
netzmacht/html Version ^2.0 || ^3.0 | — | — |
symfony/config Version ^5.4 || ^6.4 || ^7.4 | — | — |
contao/core-bundle Version ^4.13 || ^5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.