The compact artifact has clear consumer documentation and a simple dependency surface. Recent release activity is present, but the repository shows no commits in the last three months and has no security policy.
64%
Total Score
75
100
88
50
The artifact includes a LICENSE.txt file and declares GPL-2.0-or-later, so licensing is transparent. The detected GPL-2.0 text is narrower than the manifest declaration, creating a minor inconsistency.
The repository recorded zero commits and zero active maintainers during the last three months. That is meaningful evidence of thin recent maintenance, although the current release shows the project has not been fully abandoned.
Composer is used for the build, providing expected ecosystem tooling. No security scanning tools are configured, which leaves a modest transparency and maintenance gap.
The repository has no security policy. This does not show a vulnerability, but it reduces transparency about how security issues are reported and handled.
No GitHub Actions workflows were present, so there are no workflow findings or unsafe permissions to weigh. This also means automated build and security checks are not evidenced by this signal.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.0 || ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.