The MIT license and compact dependency set make the package straightforward to evaluate. Its maintenance coverage is weak, with no security policy or scanning and no recent project activity.
8%
Total Score
0
42
50
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption risk because the package is explicitly withdrawn from active use.
The package has only 3 releases, all concentrated between July 6 and July 10, 2017, with no release in about 9 years. This strongly indicates abandonment rather than active maintenance.
The repository had 0 commits and 0 active maintainers in the last 3 months, consistent with its archived state. There is no observed development activity to offset the maintenance risk.
The source repository is archived, and it was last pushed about 8 years ago. An archived project is unlikely to receive fixes or compatibility updates.
Composer is used for builds, which is appropriate for this package, but no security-scanning tools are present. That is a modest transparency and maintenance gap, though less significant than the abandonment signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ^3.2 || ^4.1 | — | — |
symfony/var-dumper Version ^3.3 | — | — |
contao-community-alliance/composer-plugin Version ~2.4 | ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.