Tests in the source tree, a clear license, and organization backing support maintenance confidence. Dependabot is configured, but the workflow audit found an always-true condition and all six action references are unpinned.
58%
Total Score
75
93
50
The package has a long history with 20 releases since October 2013, but it has made no release in the last 12 months; the latest release was about 18 months ago. This points to slowing maintenance rather than abandonment by itself.
The repository recorded 0 commits and 0 active maintainers in the last three months. With no recent registry releases, this is concrete evidence of currently inactive development.
The linked repository has no security policy. This is a transparency gap, though it is partly mitigated by the presence of Dependabot scanning.
All 6 of 6 action references are unpinned, and the audit found a high-confidence, high-severity always-true condition. The workflow has no untrusted checkout or script-injection trigger, so these remain meaningful hygiene and correctness concerns rather than a severe supply-chain risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
metamodels/core Version ^2.3 | — | — |
contao/core-bundle Version ^4.13.0 <5.0 | — | — |
symfony/http-kernel Version ^5.4 | — | — |
symfony/event-dispatcher Version ^5.4 | — | — |
symfony/dependency-injection Version ^5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.