The package has clear documentation, an explicit license, and a recently updated source repository. Its single active contributor and workflow audit findings add maintenance and release-process risk.
43%
Total Score
50
81
50
Packagist marks the entire package as abandoned, with no distinct replacement identified. This is a major adoption and maintenance warning even though newer source activity exists.
The package has existed since 2017 and released once in the last 12 months, with the latest release on August 12, 2026. The recent release is positive, but the long median interval indicates a slow cadence.
One contributor made all recent commits, and the repository owner is an individual rather than an organization. This leaves maintenance dependent on one person.
Only one commit was recorded in the last three months, showing some recent activity but a thin maintenance cadence.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14.3 | — | — |
typo3/cms-backend Version ^14.3 | — | — |
typo3/cms-frontend Version ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.