The repository has recent activity and the release includes notes, while the organization-backed project remains identifiable. The single recent contributor and absent security safeguards add modest maintenance risk.
78%
Total Score
83
94
75
Only one commit was recorded in the last three months, showing limited recent development activity. The recent release and repository push partly compensate, but the activity level still adds a modest maintenance concern.
Composer build tooling is present, but no security-scanning tools were detected. This is a transparency and maintenance-hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy. That weakens vulnerability-reporting transparency, though it does not by itself indicate abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ^5.3 | — | — |
symfony/http-kernel Version ^5.4 || ^6.4 || ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.