Its only two releases were published over seven years ago, and the repository is archived. The license files exist, but their GPL-3.0 text conflicts with the LGPL-3.0+ declaration.
12%
Total Score
30
Packagist marks the entire package as abandoned, with no replacement provided. Package-level deprecation is a direct warning against taking a new dependency.
The package has only two releases, both from January 2019, with no releases in the last 12 months; this indicates prolonged abandonment rather than active maintenance.
The linked repository is archived and was last pushed over seven years ago, so ongoing fixes and maintenance should not be expected.
A license file is present, but it is detected as GPL-3.0 while the manifest declares LGPL-3.0+, creating a licensing mismatch that should be resolved before adoption.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ~3.5 | — | — |
codefog/contao-haste Version ~4.21 | — | — |
contao-community-alliance/composer-plugin Version ~2.4 | ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.