The small codebase has no tests or security policy, and its documented support is limited to Contao 4.4 LTS. Organization backing and a clear MIT declaration provide some transparency, but not enough to offset the age and design concerns.
15%
Total Score
50
100
69
75
The latest release was published in February 2019, and there have been no releases in more than seven years. This is strong evidence of abandonment for a framework extension.
There were zero commits and zero active maintainers in the last three months, consistent with a project that has received no source updates for more than seven years.
A readable README is present, but it documents support only for Contao 4.4 LTS and explicitly warns that login codes are stored in plain text and the extension is not secure for protected member areas. The absence of tests and a changelog is normal for a published artifact and is not itself a gap.
Composer build tooling is present, but no security-scanning tooling was detected. This is a modest transparency and maintenance gap, especially for an authentication-related extension.
The repository is not marked archived, but its last push was in February 2019. The stale repository state is more directly reflected by the commit activity evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version 4.4.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.