The prerelease status and tiny, inactive project provide little confidence for a dependency. Its explicit Composer dependencies and declared license are positive, but they do not offset the lack of continued maintenance.
12%
Total Score
0
40
Packagist marks the entire package as abandoned, with no replacement provided. That is a direct warning against taking a new dependency on this release.
The package has had only two releases, both in April 2014, and none in over 12 years. This strongly indicates abandonment rather than an actively maintained release line.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release hiatus. The repository's last push was also in 2014.
The repository uses Composer, but it has no security-scanning tooling. This is a secondary hygiene gap beside the much stronger abandonment evidence.
The assessed version is still a release candidate, and all recent releases are prereleases. That leaves the package with both maturity and maintenance concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core Version >=3.1,<4 | — | — |
metamodels/core Version >=1,<2 | — | — |
metamodels/attribute_select Version >=1,<2 | — | — |
contao-community-alliance/composer-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.