The repository is organization-backed and not archived, with the package name matching its source repository. Consumer documentation is absent, and the repository has no security policy or security scanning.
62%
Total Score
75
100
78
75
The artifact has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the absent README is a minor documentation gap for a library consumers must integrate.
The package has only 3 releases across nearly 8 years, with no release in the last 12 months and a median interval of about 2 years and 10 months. This indicates slow maintenance, though the package may be intentionally stable.
The repository recorded no commits and no active maintainers during the last 3 months. The recent push provides some counterevidence, but current development activity is still limited.
The repository has 0 stars, 1 fork, and 2 watchers. This indicates limited adoption evidence, but popularity is only supporting evidence and does not outweigh the maintenance signals.
Composer is used for builds, but no security-scanning tools are configured. This is a modest transparency and maintenance gap rather than evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ~4.4 || ~5.3 | — | — |
qbus/contao-transient-model Version ^1.2 | — | — |
contao-community-alliance/composer-plugin Version ~2.4 || ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.