Documentation and licensing are in place, and the repository clearly matches the package. Maintenance has stopped since October 2021, with no recent commits and six open issues, making long-term compatibility a concern.
45%
Total Score
50
100
86
50
The latest release was over four years ago, and there were no releases in the last 12 months. The package has a substantial history of 19 releases, but the current gap points to abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the multi-year release gap and indicating no visible ongoing maintenance.
The package runs a post-autoload-dump lifecycle script, which adds install-time behavior that consumers should understand. No evidence shows that this script is harmful, so the impact is limited.
Six issues remain open, with no issues or pull requests opened or closed in the last month. This suggests unresolved maintenance needs, although the issue count alone is not severe.
The repository has no security policy, leaving no stated process for reporting or handling vulnerabilities. This is a transparency gap, but it is less significant than the lack of recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^10.4 | — | — |
typo3/cms-backend Version ^10.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.