Professional, full-featured and high performance TYPO3 e-commerce extension for online shops and complex B2B projects
67%
Total Score
caution
Usable with caveats: recent work is concentrated in one contributor, despite a long and active release history.
The manifest declares LGPL-3.0-or-later, while the artifact license file was detected as GPL-3.0. Although both the artifact and repository contain license files, the declaration mismatch warrants clarification before adoption.
The package defines a post-update-cmd lifecycle script. Such hooks can be legitimate, but they add install or update-time behavior that should be understood before deployment.
One contributor made all two commits in the last three months, giving that contributor a 100% share. The project is not identified as organization-owned, so this concentration is a genuine continuity concern.
Only two commits were recorded in the last three months, with one active maintainer. Recent source activity is present but sparse, so this modestly lowers confidence in ongoing maintenance momentum.
The repository uses Composer and Phing for builds, which supports repeatable project maintenance. No security-scanning tools were detected, leaving a security-process gap.
| Title | Versions | Severity |
|---|---|---|
CVE-2021-28380 aimeos/aimeos-typo3 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 19.10.12 and 20.0.0 - 20.10.5. | 0.0.0 - 19.10.1220.0.0 - 20.10.5 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.2 | — | — |
typo3/cms-core Version ^13.4||^14.3 | — | — |
aimeos/ai-typo3 Version ~2026.04 | — | — |
typo3/cms-backend Version ^13.4||^14.3 | — | — |
typo3/cms-extbase Version ^13.4||^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.