The README and declared LGPL license provide basic consumer documentation and usage terms. However, the project has had no commits for about 7 years, and its sole registry maintainer cannot offset the package's abandoned status.
15%
Total Score
25
58
50
Packagist marks the entire package as abandoned, with no distinct replacement identified. This is a direct warning against taking a new dependency on the release.
The package has eight releases but none in the last 12 months; its latest release was in March 2019, about 7 years ago. This indicates prolonged inactivity rather than an actively maintained dependency.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the package's long release gap. The absence of recent maintenance materially raises abandonment risk.
Only one account has registry publish access. A narrow maintainer base provides little continuity when the project also shows no recent release or commit activity.
The repository name does not match the package name and its README does not mention the package, so the linkage is less transparent. The matching repository contents partly mitigate this concern, but the mismatch remains a caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ^3.2.1 || ^4.4 | — | — |
contao-community-alliance/composer-plugin Version ^2.4 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.