Usable with caveats: it is a licensed, established package with repository tests, organization backing, and no deprecation or risky workflow findings. However, there have been no releases in about 18 months and no commits in the last three months, while repository security-policy and workflow-permission hygiene are limited.
62%
Total Score
88
50
94
80
Ten runtime dependencies, including framework and database components, create meaningful compatibility and maintenance surface, but the profile is coherent for a framework integration package.
The package has existed since January 2014 with 15 releases, but it has had no release in the last 12 months; the latest release was about 18 months ago, which raises maintenance concern.
There were zero commits and zero active maintainers in the last three months, consistent with the long gap since the latest release and indicating slowed maintenance.
The repository has no security policy, leaving vulnerability-reporting expectations and response guidance undocumented.
The only workflow lacks top-level token permissions. No write permissions were observed, but explicitly restrictive permissions would provide better workflow hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.3 | — | — |
metamodels/core Version ^2.3 | — | — |
contao/core-bundle Version ^4.13.0 <5.0 | — | — |
symfony/http-kernel Version ^5.4 | — | — |
symfony/dependency-injection Version ^5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.