The package has a clear README, repository tests, a matching organization-owned project, and a valid license. Maintenance has slowed, while the workflow uses six unpinned actions and contains a high-confidence condition flaw; no security policy is published.
64%
Total Score
50
100
93
50
The repository recorded zero commits and zero active maintainers in the last three months. Because the latest release is older than that period, this indicates slowed maintenance and raises abandonment risk.
There are five open issues, with one new issue and no issues or pull requests closed in the last month. This is limited evidence of unresolved maintenance work, though not enough to establish abandonment alone.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanner is a maintenance and assurance gap, partially offset by the repository's tests and other quality configuration.
The repository has no security policy. For a package integrated into a framework, this reduces transparency about vulnerability reporting and handling.
All six analyzed action references are unpinned, which weakens build reproducibility, and the audit found a high-confidence unsound condition. The workflow has no untrusted checkout or script-injection finding, so these are hygiene concerns rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.3 | — | — |
symfony/config Version ^5.4 | — | — |
metamodels/core Version ^2.3 | — | — |
symfony/routing Version ^5.4 | — | — |
contao/core-bundle Version ^4.13.0 <5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.