The small repository footprint and absent security policy add little assurance. The package is licensed and not deprecated, but its maintenance record is too old for a dependable integration.
38%
Total Score
25
60
50
The last release was in November 2020, and there have been no releases in the past 12 months. This long period without updates is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the package's long release gap and providing no evidence of current maintenance.
Three issues remain open, with no issues or pull requests opened or closed in the past month. This reinforces the lack of recent project activity.
The repository name does not match the package name, and the README does not mention the package. That makes ownership and release provenance less clear, beyond an ordinary monorepo sub-package mismatch.
Composer build tooling is present, but no security-scanning tools were detected. The build setup is ordinary, while the missing scanning coverage modestly reduces assurance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.0 | — | — |
contao/core-bundle Version ^4.9 | — | — |
contao/newsletter-bundle Version ^4.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.