Usable with caveats: the release is licensed, documented, tested, stable, and not deprecated or archived. However, it has had no release in over two years and no commits in the last three months, with no security policy or automated security scanning.
62%
Total Score
67
88
88
The package has 14 releases since October 2020, but none in the last two years and latest release activity stopped in March 2024. That long release gap raises maintenance and compatibility concerns.
There were zero commits and zero active maintainers in the last three months. Combined with the long release gap, this is meaningful evidence of currently inactive maintenance.
Five issues remain open, with no new or closed issues and no merged pull requests in the last month. This suggests limited recent responsiveness, though it is not by itself evidence of abandonment.
Composer is used for builds, but the repository has no security scanning tools. For a dependency package this is a transparency and detection gap, although no workflows are present to introduce workflow-specific risk.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ^4.4 || ^5.0 | — | — |
contao-community-alliance/composer-plugin Version ^2.4.0 || 3.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.