The package includes a clear README, an explicit LGPL-3.0+ license, and no install-time scripts. Its narrow Contao compatibility and five runtime dependencies also make adoption harder, with no recent activity to support maintenance.
15%
Total Score
0
50
64
50
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption risk because the registry itself indicates the package is no longer maintained for use.
The package has only one release, published about 10 years ago, with no releases in the last 12 months. This strongly indicates abandonment rather than an actively maintained stable release.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap. The organization-owned repository provides ownership context but no observed maintenance activity.
The package declares five runtime dependencies, including Contao and related TinyMCE components. This is a meaningful integration and compatibility burden, especially for a package whose stated compatibility ends below Contao 3.6.
Composer is used as the build tool, providing expected packaging support. No security scanning tools were detected, which is a minor transparency gap but not the primary reason this release is unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core Version >=3.3.0,<3.6 | — | — |
rsclg/tiny-mce-triathlon-icons Version ~1.0 | — | — |
cliffparnitzky/tiny-mce-bundle-all Version ~2.10 | — | — |
contao-community-alliance/composer-plugin Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.