The repository is small and has no security policy or automated security scanning. It is not archived, is licensed, and has no install-time scripts, which limits the concern.
58%
Total Score
50
79
75
The package has no README, tests, or changelog, and the source repository also reports no tests or changelog. The missing consumer documentation and validation evidence reduce transparency for this library.
The package has only three releases, with the latest published in March 2022 and none in the following four years and six months. This is a substantial maintenance concern for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months. The repository is not archived, but current development activity is absent.
Composer is used for builds, but no security-scanning tools are present. That leaves dependency and code security checks less visible, though it does not by itself indicate a supply-chain failure.
The repository has no security policy, so there is no stated process for reporting or handling vulnerabilities. This is a hygiene gap rather than evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ^4.9 | — | — |
contao-community-alliance/composer-plugin Version ~2.4 || ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.