The organization-backed repository matches the package and has a clear MIT license and readme. One contributor made only one recent commit, while the workflow uses an unpinned action and has no security policy.
68%
Total Score
67
92
67
The latest registry release was published over three years ago, and there were no releases in the last 12 months. Recent repository activity partly offsets the concern, but the shipped release cadence remains stale.
All recent commits came from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown to reduce the immediate concentration risk.
The repository recorded only one commit in the last three months from one active maintainer. This shows some maintenance, but limited recent activity lowers confidence in ongoing release support.
The repository has no published security policy. This is a transparency and issue-handling gap, though it is not evidence of a security incident.
The workflow is fully analyzed, uses read-only permissions, and has no audited findings, but its only action reference is unpinned. That leaves avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao/core-bundle Version ^4.13 || ^5.0 | — | — |
symfony/polyfill-php80 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.