The extension is small and clearly documented, with a declared license and a recent stable release. Maintenance evidence is thin, though organizational ownership reduces the risk from one recent contributor.
70%
Total Score
67
100
88
75
The package has five releases over about three years, with one release in the last 12 months and the latest released recently. This supports ongoing maintenance but indicates a modest release cadence.
All recent commits came from one contributor. The repository is organization-owned, which provides some handoff capacity, but no second active contributor is shown in this period.
Only one commit from one active maintainer was recorded in the last three months. The recent release offsets this somewhat, but the short-term maintenance evidence remains thin.
Composer is used for builds, but no security-scanning tooling was detected. For this small extension this is a modest transparency gap rather than a severe risk.
The repository has no security policy. This weakens vulnerability-reporting transparency, although the package's small scope and other clear project metadata limit the impact.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.0 || ^14.0 | — | — |
typo3/cms-filemetadata Version ^13.0 || ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.