Contao search widget to search and select records from any provider. This is a developer tool.
62%
Total Score
caution
Usable with caveats: this is a new release with only two commits from one contributor.
The package is only 43 days old and has one release, so there is not enough history to demonstrate sustained maintenance. Its youth limits the evidence rather than proving abandonment.
All 2 recent commits came from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository has only 2 commits in the last 3 months, providing limited evidence of active maintenance for a newly released package.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, not evidence of an unsafe release.
The single workflow uses read-only permissions and has no detected audit findings, but its only action reference is unpinned. That leaves avoidable build reproducibility and action-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.28 | — | — |
lcobucci/jwt Version ^5.6 | — | — |
psr/container Version ^2.0 | — | — |
symfony/asset Version ^7.4 || ^8.0 | — | — |
lcobucci/clock Version ^3.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.