The release line is stable, the repository is not archived, and the package has a normal dependency footprint. Its very short README and absent security scanning reduce transparency; confirm the intended license before adoption.
63%
Total Score
67
100
81
75
The artifact contains a license file, but it identifies MIT while the manifest declares LGPL-3.0-or-later. That mismatch creates a genuine licensing concern despite the release being explicitly licensed.
A GitHub release with notes exists for this exact version, which documents the change. The 27-character README is unusually sparse for a Contao integration and limits consumer guidance.
The package and repository are owned by the same individual account rather than an organization. This is consistent ownership, but it provides less visible backing than an organization-supported project.
There were zero commits and zero active maintainers in the last three months. Although the repository was pushed recently and the registry had a release about four months ago, this still signals a thin current maintenance window.
Composer is used as the build tool, but no security-scanning tooling is present. The missing scanning is a modest transparency and maintenance gap, not evidence of unsafe behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ^4.9 || ^4.13 | — | — |
symfony/http-kernel Version ^4.4 || ^5.1 | — | — |
symfony/dependency-injection Version ^4.4 || ^5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.