The last release and repository update were about eight years ago, with no commits or active maintainers in the past three months. Documentation, release notes, matching source, and a declared license help, but there is no security scanning and the project has only minimal community activity.
38%
Total Score
50
100
72
83
The latest release was about eight years ago, and there were no releases in the last 12 months. This is strong evidence of abandonment for a package that may need compatibility or security fixes.
The repository had zero commits and zero active maintainers in the past three months, reinforcing that maintenance has stopped rather than merely slowed.
There was one open issue and no issue or pull-request activity in the past month, providing no evidence of active maintenance or community support.
The repository has one star and one fork, so there is little community adoption to provide independent support or scrutiny. Popularity is supporting evidence, but this reinforces the maintenance concern.
Composer build tooling is present, but no security-scanning tooling was detected. The build setup is a positive; the missing security checks leave a meaningful hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ~3.5 || ~4.4 | — | — |
terminal42/contao-leads Version ~1.2 | — | — |
contao-community-alliance/composer-plugin Version ~2.4 || ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.