This is a mature, actively released Contao extension with a stable version, clear licensing, an organization-backed repository, and a source tree that matches the package and documents its use. The main concerns are that the repository recorded no commits or active maintainers in the last 3 months despite the recent release, and it has no tests, changelog, security policy, or security scanning; these reduce maintenance and transparency confidence but do not indicate that the package is unfit to use. Overall, it appears reasonable to depend on with normal version pinning and upgrade review.
78%
Total Score
88
100
89
90
A substantive README documents requirements, installation, configuration, and commands, but neither the artifact nor repository contains tests or a changelog. For a small extension this is a real maintenance-transparency gap, though the documentation partly compensates.
The repository recorded 0 commits and 0 active maintainers over the last 3 months. This is concerning given the otherwise recent release history, although the recent repository push provides some compensating freshness evidence.
Composer is used as the build tool, but no security scanning tools are configured. Composer provides appropriate packaging structure; the missing scanning is a modest transparency and security-process gap.
No repository security policy was found. This weakens vulnerability-reporting transparency, but the absence is a caution rather than a severe adoption risk for this small package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.7 || ^4.3 | — | — |
symfony/config Version ^6.4 || ^7.4 || ^8.0 | — | — |
symfony/console Version ^6.4 || ^7.4 || ^8.0 | — | — |
symfony/routing Version ^6.4 || ^7.4 || ^8.0 | — | — |
contao/core-bundle Version ^5.0 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.