Usable with caveats: it is a clearly packaged, licensed, non-deprecated extension with a matching repository, but it is brand new and has no demonstrated maintenance history yet. The repository also lacks security scanning and a security policy, so longer-term reliability remains unproven.
63%
Total Score
50
100
88
90
Only one registry account has publishing access. That is a limited publishing base, though the package is backed by a matching source repository, so this is a resilience concern rather than evidence of abandonment.
The package is published under one user namespace and its repository is owned by a different individual account, rather than an organization. This provides less visible institutional backing and leaves continuity dependent on a small owner base.
This package is only 0 days old with two releases published within about 1 hour and 27 minutes, so there is not yet enough history to demonstrate sustained maintenance or release reliability.
The repository shows zero commits and zero active maintainers in the last 3 months, but the package itself was created today, making this primarily an absence of historical evidence rather than a demonstrated collapse in maintenance.
Composer build tooling is present, but no security scanning tools were detected. For a small PHP extension this is a hygiene gap, although it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ^4.13 || ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.