It has a clear README, tests, a matching repository, no deprecation, and no install-time scripts. However, there were no commits in the last three months, all two workflow actions are unpinned, and the declared LGPL license conflicts with the detected MIT license. The repository also lacks a security policy.
68%
Total Score
75
100
94
67
The artifact declares LGPL-3.0+ and includes a license file, but the detected license is MIT, creating a material licensing inconsistency that should be resolved before adoption.
The repository recorded zero commits and zero active maintainers during the last three months. This is concerning for maintenance continuity, although the recent release history provides some compensating evidence.
No repository security policy was found, leaving vulnerability reporting and response expectations undocumented.
The workflow audit completed successfully with no trigger, injection, or high-confidence security findings. However, both analyzed action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ^4.13 || ^5.0 | — | — |
cloudconvert/cloudconvert-php Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.