This is a generally healthy, mature TYPO3 extension with over five years of release history, a stable 6.0.0 release, an active non-archived organization-backed repository, clear licensing, tests, and a focused dependency profile. The main concerns are that repository commit activity shows no commits or active maintainers in the last three months, the repository has very low popularity, no security policy or security-scanning tooling, and no changelog; however, these concerns are partly offset by a release published on the assessment date, a recent merged pull request, and the presence of source tests and a complete package tree. It appears reasonable to depend on, with normal maintenance and update monitoring.
78%
Total Score
88
100
89
90
The repository records zero commits and zero active maintainers over the last three months, which is a meaningful maintenance concern. This is partly compensated by the current release and recent repository push, but the short-term commit signal still warrants monitoring.
The repository has only 2 stars, 0 forks, and 0 watchers. Popularity is supporting evidence rather than a verdict, but these very low counters provide little external adoption signal.
Composer is used as a build tool, but no security-scanning tools are configured. The missing scanning is a hygiene gap rather than evidence of unsafe behavior.
No repository security policy was found, reducing transparency around vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.