The README, stable version, and matching repository make the package understandable. However, one maintainer, no releases in the last 12 months, and no commits in three months indicate limited ongoing maintenance; pin this version if adopting.
53%
Total Score
50
100
88
50
Only one registry account has publish access. Because the repository is user-owned rather than organization-backed, this indicates a thin publishing and maintenance base.
The registry namespace and repository are both owned by the same user account, and the repository is not organization-backed. This supports ownership alignment but does not offset the thin maintainer base.
The package has 17 releases since January 2022, but none in the last 12 months and the latest release was in July 2025. This suggests maintenance has slowed substantially.
There were no commits and no active maintainers in the last three months. Combined with no releases in the last 12 months, this is meaningful evidence of limited ongoing maintenance.
Composer build tooling is present, but no security scanning tools were detected. This is a minor transparency and hygiene gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version * | — | — |
contao/core-bundle Version ^4.13 || ^5.0 | — | — |
codefog/contao-haste Version ^5.1 | — | — |
markocupic/zip-bundle Version ^1.0 | — | — |
symfony/webpack-encore-bundle Version ^v2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.