It has repository tests, a clear license, and automated dependency scanning. The workflow uses six unpinned actions and contains a high-confidence condition error, so CI hygiene needs attention.
55%
Total Score
50
83
50
The package has existed for about 12 years and has 13 releases, but none were published in the past 12 months; the latest release is about 18 months old. This weakens confidence in ongoing maintenance despite its long history.
The repository recorded no commits and no active maintainers in the past three months. This may reflect a stable small package, but alongside the release gap it raises abandonment risk.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a transparency gap, though it is not evidence that the package is unsafe.
All six analyzed action references are unpinned, and the audit found a high-confidence condition that always evaluates to true. The single workflow has no top-level permissions block, which is acceptable on its own, but the unpinned actions and workflow error reduce CI hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
metamodels/core Version ^2.3 | — | — |
contao/core-bundle Version ^4.13.0 <5.0 | — | — |
symfony/http-kernel Version ^5.4 | — | — |
symfony/dependency-injection Version ^5.4 | — | — |
symfony/translation-contracts Version ^2.5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.