The long release history, stable versioning, clear license, and recent publishing support ongoing maintenance. Organization backing helps, but recent work is concentrated in one contributor, security guidance is absent, and the repository does not clearly mention this package.
67%
Total Score
63
100
88
75
All 5 recent commits came from one contributor, giving the project a single-person recent commit bus factor. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository had 5 commits in the last 3 months, so work is still occurring, but the activity is limited and not broad-based.
There are 14 open issues and no issues or pull requests were opened or closed in the last month. This is a modest maintenance concern, but recent releases and commits show the project is not inactive.
The repository name does not match the package name and its README does not mention the package. Although the linked repository is plausible, the missing README reference leaves package ownership less clearly verified.
Composer is used as the build tool, but no security scanning tool is reported. The missing scanner is a hygiene gap rather than evidence that the release is unsafe by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.8 | — | — |
typo3/cms-cli Version ^3.1 | — | — |
typo3/cms-core Version ^14.3 | — | — |
typo3/cms-backend Version ^14.3 | — | — |
typo3/cms-extbase Version ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.