Risky to adopt: the latest release is still an alpha from more than seven years ago, and the repository has had no recent commits or active maintainers. It is licensed, documented, and not deprecated or archived, but the long-term abandonment risk is substantial.
38%
Total Score
33
50
71
88
The latest release was published more than seven years ago, with no releases in the last 12 months. This strongly indicates abandonment risk despite the package having 12 releases overall.
There were no commits and no active maintainers during the last three months. Alongside the release gap, this is strong evidence that maintenance has stopped.
Eleven runtime dependencies create a meaningful compatibility and maintenance surface for this older integration package, with no development dependencies shown to support testing or maintenance.
Only one registry account can publish the package. A single maintainer is not inherently unsafe, but combined with the absence of recent repository activity it increases continuity risk.
The package and repository are owned by the same individual, so the source linkage is clear. However, individual ownership provides less organizational continuity than established project backing.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^2.7 | — | — |
symfony/config Version ^3.3 || ^4.0 | — | — |
paragonie/halite Version ^4.4 | — | — |
contao/core-bundle Version ~4.4 | — | — |
codefog/contao-haste Version ~4.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.