The last registry release was nearly six years ago, and the repository has had no commits or issue activity in the past three months. It remains supported by an organization, includes tests, and is not archived, but its workflows use unpinned actions and the license texts do not fully match.
58%
Total Score
63
100
69
50
The latest release was on November 24, 2020, with no releases in the last 12 months; this is a significant maintenance concern despite six releases over the package's lifetime.
The repository recorded zero commits and zero active maintainers in the past three months, showing that active development has stopped recently.
The package declares GPL-2.0+ and includes a license file, but the detected artifact text is GPL-2.0, so the declaration and license text do not fully match.
A post-autoload-dump lifecycle script runs during installation, adding some supply-chain complexity, though this signal alone does not show harmful behavior.
There were no new or closed issues and no new or merged pull requests in the past month, with eight open issues and two open pull requests; this supports the maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^9.5 || ^10.4 || dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.