Animated timeline bundle for Contao CMS
64%
Total Score
83
100
88
50
The package declares LGPL-3.0-or-later and includes license files, but the artifact also detects MIT, creating a licensing mismatch that should be clarified before adoption.
The repository recorded zero commits and zero active maintainers during the last 3 months. Although a recent release provides some compensating evidence, this still indicates limited current development activity.
The repository uses Composer but has no detected security scanning tools. The lack of scanning is a modest transparency and maintenance gap, not evidence of abandonment by itself.
No repository security policy was found, leaving vulnerability reporting expectations undocumented. This is a moderate transparency gap for a package intended for application integration.
The single workflow was fully analyzed with no untrusted checkout or script-injection findings, but all six action references are unpinned. The workflow also lacks a top-level permissions block, which is acceptable on its own; unpinned actions remain a supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ^4.13 || ^5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.