The source includes tests, documentation, a changelog, and a repository that clearly matches the package. Licensing and security-policy coverage are missing, while the project shows no recent maintenance activity, so future compatibility and support are uncertain.
42%
Total Score
25
100
75
75
The latest release was published on January 10, 2020, and there have been no releases in the last 12 months. This is strong evidence of abandonment for a package consumers may need to keep compatible with current TYPO3 versions.
The repository recorded zero commits and zero active maintainers in the last three months. The last recorded push was in December 2021, so there is no recent maintenance capacity visible.
No declared license, license file, or repository license file was detected. That creates a concrete legal transparency gap for adopting the package.
There were no new or closed issues or pull requests in the last month, despite 32 open issues and 5 open pull requests. This suggests unresolved maintenance demand rather than an actively managed project.
The repository has no security policy. This is a modest transparency and vulnerability-reporting gap, not evidence of malicious behavior by itself.
| Title | Versions | Severity |
|---|---|---|
CVE-2013-5322 bednee/cooluri is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 1.0.30. | 0.0.0 - 1.0.30 | High |
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^9.5 | — | — |
friendsoftypo3/typo3db-legacy Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.