The package has a README, a matching repository, and no install scripts. Its declared GPL-2.0-or-later conflicts with the detected GPL-3.0, and the repository has no security policy.
64%
Total Score
50
100
81
75
The artifact includes a license, but the manifest declares GPL-2.0-or-later while the license file is detected as GPL-3.0; the mismatch needs clarification before adoption.
The repository is owned by a user account rather than an organization, so the concentrated maintainer and contributor activity is not visibly offset by broader organizational backing.
There have been only two releases over about 6 months, with the latest release about 3 months ago and a median interval of about 93 days; this shows limited but not vanished release activity.
All two recent commits came from one contributor, giving the project a single-person maintenance dependency with no observed backup contributor.
Only two commits were recorded in the last 3 months, indicating a thin maintenance history even though activity has not stopped.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14.3 | — | — |
friendsoftypo3/content-blocks Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.