There are no repository tests or security scanning, and the README contains only 19 characters. The package remains correctly identified and licensed, but its maintenance evidence is too thin for a dependable dependency.
38%
Total Score
50
100
75
50
The package has had only two releases, both in August 2018, with no releases in the last 12 months and no subsequent release activity. This is strong evidence of abandonment risk for a package intended as an application dependency.
The artifact includes a README and has a GitHub release for this version, but the README is only 19 characters and the repository has no tests or changelog. Missing tests are a maintenance concern here because no other provided signal compensates for the lack of validation evidence.
The repository has one open issue but no new or closed issues, pull requests, or merges in the last month. This adds limited evidence of inactivity rather than proving abandonment on its own.
Composer is used for builds, but no security scanning tools are present. The absence of scanning is a modest transparency and maintenance gap for a dependency.
The repository has no security policy, leaving no documented path for reporting or handling vulnerabilities. This is a transparency gap, though it is less severe than the prolonged lack of releases.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ^4.4.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.