There is no repository security policy, and the project has only 2 stars and 3 forks. The package is licensed, non-deprecated, and has a focused dependency set.
62%
Total Score
50
100
81
50
The package has made no releases in the last 12 months, after only three releases over roughly three and a half years. This indicates slow maintenance, though the latest release is still recent enough to avoid an abandonment verdict on its own.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. The repository was pushed at the latest release, but current development activity is not evident.
The repository has only 2 stars, 3 forks, and 1 watcher, providing little external evidence of broad adoption or review. Low popularity is supporting caution only and does not outweigh the observed repository and release history by itself.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest process gap rather than a severe supply-chain concern.
The repository has no security policy. For an extension that manages Apache Solr connections and records, this is a transparency gap, although it does not by itself show unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12||^13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.