Regular releases and a matching, licensed source tree provide useful maturity signals. The project has no recent commit activity, security scanning, or security policy, so maintenance and response capacity remain uncertain.
61%
Total Score
50
81
75
The artifact includes a LICENSE.txt file and declares GPL-2.0-or-later, but the detected GPL-2.0 text is narrower than that declaration, creating a licensing clarity concern.
The repository recorded zero commits and zero active maintainers during the last three months, which weakens confidence that issues and compatibility work will be handled promptly.
The repository has 0 stars, 0 forks, and 1 watcher, indicating a very small user and contributor footprint; this is supporting caution rather than proof of poor quality.
Composer is used for the build, but no security scanning tools are configured, leaving a gap in automated security hygiene.
The repository has no security policy, so there is no documented reporting and response process for vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-frontend Version ^13.4.5 || ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.