No commits were recorded in the last three months despite a recent push, leaving maintenance uncertain. The license file says GPL-3.0 while the manifest declares GPL-2.0-or-later, and the repository has no security policy; the stable, non-deprecated release and matching repository provide some reassurance.
58%
Total Score
50
83
75
The manifest declares GPL-2.0-or-later, but the detected LICENSE file says GPL-3.0. Although both are copyleft licenses and license files exist in the package and repository, the mismatch needs clarification before adoption.
The package has four releases over 192 days, with the latest published about four months before collection. This shows some release activity but leaves a meaningful recent-cadence gap.
The repository recorded zero commits and zero active maintainers in the last three months. A push on 2026-05-27 shows the repository is not archived, but it does not offset the absence of recent commit activity.
The linked repository has no security policy. This is a transparency and maintenance gap, though it is not severe enough to make the release unfit on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14 | — | — |
friendsoftypo3/content-blocks Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.