The MIT license, matching repository, and clear README make the package easy to inspect. Do not adopt it for new work; its abandoned status leaves compatibility and support risks with no stated replacement.
8%
Total Score
0
50
50
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption concern because the registry explicitly signals that maintenance has ended.
The latest release was published nearly nine years ago, with no releases in the last 12 months. The long release gap materially increases abandonment and compatibility risk.
The repository had no commits and no active maintainers in the last three months. Together with the archived repository and stale release history, this confirms inactive maintenance rather than a merely slow cadence.
The linked source repository is archived, and it was last pushed nearly seven years ago. Archived source is a strong indication that fixes and compatibility updates are no longer expected.
The repository has no security policy or security-scanning tools. This adds a transparency and response gap, although the abandonment signals are the primary reason for the low score.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.0 | — | — |
contao/core-bundle Version ^3.2 || ^4.1 | — | — |
contao-community-alliance/composer-plugin Version ~2.4 | ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.