The project is easy to inspect, with release notes, a README, focused dependencies, and organization backing. Its limited maintenance and security process reduce confidence for long-term use.
68%
Total Score
75
100
88
75
The package has four releases over about 4 years, with only one release in the last 12 months and a median interval of about 16 months. The recent 3.0.0 release provides some evidence of continued maintenance, but the cadence is sparse.
There were no commits and no active maintainers during the last 3 months. The recent release partly offsets this, but the lack of ongoing activity raises abandonment risk.
Composer is used for the build, but no security-scanning tools were detected. This is a process gap for a package that handles API-token-based CDN operations.
The repository has no security policy. That weakens transparency around reporting and handling vulnerabilities, although it does not by itself indicate an active security problem.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 || ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.