Package Health

ameos/ameos_tarteaucitron

This is a mature, actively released Composer package with 64 releases over roughly 7 years, nine releases in the last 12 months, a stable non-prerelease version, an unarchived repository, clear GPL licensing, and a substantial documented file tree. The main concerns are that repository commit activity was absent over the last 3 months, the package has only one registry maintainer, no tests or changelog were detected, and the repository has no security scanning or security policy; its very low popularity also provides little independent adoption evidence. Overall, it appears usable to depend on, but maintenance continuity and security-process transparency should be monitored.

Latest 4.1.1PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Are you affected? Scan for Free

Health Score Breakdown

Maintainerscaution

Only one registry account, Ameos Team, has publish access. This is a limited publishing base, although the linked repository supplies additional project context and recent release activity.

Package scaffoldingcaution

A substantial README is present, but neither the artifact nor repository contains tests or a changelog. These are meaningful transparency and maintenance gaps, though the README and GitHub Releases provide some documentation compensation.

Project backingcaution

The repository is owned by the user account 'ameos', not an organization, so the single registry maintainer is not clearly compensated by organization-backed ownership.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers during the last 3 months, which materially weakens confidence in ongoing maintenance despite the recent release and merged pull requests.

Repo popularitycaution

The repository has only 1 star, 4 forks, and 2 watchers. Low popularity is not disqualifying for a specialized TYPO3 extension, but it provides little supporting evidence of broad community adoption.

Vulnerabilities

TitleVersionsSeverity
CVE-2022-33155
ameos/ameos_tarteaucitron is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.2.23.
0.0.0 - 1.2.23
Medium

Package versions

Maintainers

Ameos Team

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^10.4 | ^11.5 | ^12.4 | ^13.1 | ^14.3 | dev-master
—
—
typo3/cms-backend
Version ^10.4 | ^11.5 | ^12.4 | ^13.1 | ^14.3 | dev-master
—
—
typo3/cms-frontend
Version ^10.4 | ^11.5 | ^12.4 | ^13.1 | ^14.3 | dev-master
—
—

Weekly Downloads

Info

Last Published
21 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform