Unfit to use: this package is marked abandoned on Packagist and has a replacement package. Although it has recent releases and a valid license, repository activity is absent and the linked repository does not identify this package clearly.
20%
Total Score
0
67
50
Packagist marks the package abandoned and points to respinar/contao-redirection as its replacement. Package-level abandonment is a severe adoption risk even though the release itself is not individually withdrawn.
The repository shows no commits and no active maintainers in the last three months. This weakens the evidence of ongoing maintenance and compounds the package-level abandonment concern.
The artifact includes a README but no tests or changelog, and the repository also lacks them. For a functional framework extension, this leaves behavior and release history less verifiable.
The repository name does not match the package name and its README does not mention the package, so the linkage is not clearly established. This reduces transparency about the source behind the release.
No security policy is present in the linked repository. This is a transparency gap, although it is secondary to the stronger abandonment and maintenance concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
psr/cache Version ^3.0 | — | — |
contao/core-bundle Version ^5.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.