A matching repository has tests, a clear license, and dependency scanning. The missing security policy and workflow hygiene add modest transparency and maintenance concerns.
68%
Total Score
75
94
75
The package is mature, with 18 releases since 2013, but it has had no release in the past 12 months; that suggests maintenance has slowed.
There were no commits or active maintainers in the past 3 months, which is a concrete sign of currently limited maintenance activity.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
The only workflow has all 6 action references unpinned and contains a high-confidence unsound condition; no untrusted checkout or injection path was found, so this is workflow hygiene rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
metamodels/core Version ^2.3 | — | — |
contao/core-bundle Version ^4.13.0 <5.0 | — | — |
symfony/http-kernel Version ^5.4 | — | — |
metamodels/attribute_select Version ^2.3 | — | — |
symfony/dependency-injection Version ^5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.