Usable with caveats: it is a stable, non-deprecated package with frequent releases and a recent repository update, but maintenance is concentrated in one contributor and the project lacks a README, tests, changelog, and security policy.
62%
Total Score
50
88
75
The published artifact has no README, tests, or changelog, and the repository also reports no tests or changelog. The absence of tests and a changelog is not inherently problematic for a published Contao extension, but the missing README reduces consumer transparency.
The source repository is owned by an individual account, while the registry namespace is different. The linked repository name matches the package name, so the source appears appropriately connected, but no organizational backing compensates for the narrow maintainer base.
All commits in the last three months came from one contributor, giving the project a very concentrated bus factor. Because the repository owner is an individual rather than an organization, there is no provided backing signal to offset that concentration.
Only one commit was recorded in the last three months, from one active maintainer. This is a real maintenance-capacity concern, despite the package's strong release frequency.
The repository uses Composer for builds, which fits this PHP package, but it reports no security-scanning tools. This is a transparency and review gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ^5.7 | — | — |
contao/news-bundle Version ^5.7 | — | — |
contao/calendar-bundle Version ^5.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.