The package has a clear license, a consumer-facing README, and no install-time scripts or workflow findings. It has no tests or security policy, limiting evidence for safe ongoing changes.
58%
Total Score
50
100
83
83
Only two releases have been published since October 2021, with no releases in the last 12 months and a long median interval of about 889 days. Recent repository activity partly offsets the sparse release cadence, but registry maintenance evidence remains thin.
All recent commits came from one contributor, leaving maintenance highly concentrated and creating a meaningful continuity risk for a user-owned project.
There was one commit in the last three months from one active maintainer. That is recent activity, but the very low volume gives limited evidence of sustained maintenance.
The repository name does not match the package name and its README does not mention the package. Although a subpackage naming mismatch can be normal, the missing README reference leaves some uncertainty that this repository is the intended source.
The repository has no security policy, so users have no documented channel or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ^4.13 || ^5.0 | — | — |
plenta/contao-encryption Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.