The repository remains active in its organization and includes tests, dependency scanning, and a clear license. Maintenance has stalled since March 2025, while the workflow contains a high-confidence condition error and all six action references are unpinned.
55%
Total Score
67
50
93
67
The package declares eight runtime dependencies, including framework and project components. This is a meaningful integration surface, but not unusually broad evidence of poor health on its own.
The package has 17 releases over more than 13 years, but none in the last 12 months; the latest release was about 18 months ago. This points to a substantially slowed maintenance cycle.
The repository had zero commits and zero active maintainers in the last three months, reinforcing that maintenance has currently stalled.
There is only one open issue and no issue or pull-request activity in the last month. This is consistent with a quiet project, though it is weaker evidence than the direct commit gap.
The repository has no security policy. For a maintained library this reduces vulnerability-reporting transparency, though the package does use Dependabot.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
metamodels/core Version ^2.3 | — | — |
contao/core-bundle Version ^4.13.0 <5.0 | — | — |
symfony/http-kernel Version ^5.4 | — | — |
symfony/event-dispatcher Version ^5.4 | — | — |
symfony/dependency-injection Version ^5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.