The GPL-3.0 license and Composer build setup provide basic transparency, while the repository has no security scanning or security policy. The artifact includes a README, but its sparse documentation limits confidence for integration.
18%
Total Score
0
50
75
Only two releases exist, with the latest published in May 2016 and none in about 10 years. This strongly indicates abandonment for a package intended as a maintained TYPO3 dependency.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with its long period of inactivity and archived state.
The linked repository is archived and was last pushed in January 2018, about 8 years ago. Archival status is a severe maintenance and adoption risk.
The repository name does not match the package name and its README does not mention the package. Although name mismatches can occur in subpackages, the missing README reference raises concern that the repository may not clearly represent this package.
Composer build tooling is present, but no security scanning tools were detected. The tooling supports reproducible project management but provides little evidence of ongoing security maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version * | — | — |
typo3/cms-fluid Version * | — | — |
typo3/cms-extbase Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.