The project has an organization-backed repository, tests, a clear license, and active dependency scanning. Its maintenance has gone quiet, while workflow references are not pinned and one workflow condition is unsound.
61%
Total Score
67
90
The package has 14 releases over more than 13 years, but none in the last 12 months; its latest release was about 18 months ago. This indicates slowing maintenance despite a long release history.
The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the absence of recent registry releases rather than showing active upkeep.
There were no new or closed issues or pull requests in the last month, with one issue still open. This is consistent with a quiet project, though the small issue backlog limits the severity.
The workflow audit completed fully and found no untrusted checkout or script-injection path, but all 6 action references are unpinned. It also found a high-confidence unsound condition; these are workflow hygiene concerns rather than a severe dependency risk on their own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.3 | — | — |
metamodels/core Version ^2.3 | — | — |
contao/core-bundle Version ^4.13.0 <5.0 | — | — |
symfony/http-kernel Version ^5.4 | — | — |
symfony/dependency-injection Version ^5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.