The package is small and clearly identified, with a license and usable README. Its source has been inactive for over nine years, and there is no security policy or scanning tooling to support continued maintenance.
12%
Total Score
25
50
67
Packagist marks the entire package as abandoned, with no replacement provided. This directly indicates that maintainers no longer support depending on this release.
The package has only five releases and none in the last 12 months; its latest release was in April 2017. The long absence of releases is consistent with the archived and abandoned status.
There were no commits and no active maintainers in the last three months. Together with the archived repository, this confirms that ongoing maintenance capacity is absent.
The linked repository is archived and was last pushed in April 2017, so it is no longer maintained. This is a severe abandonment risk for a project dependency.
Install and update lifecycle scripts run automatically, creating additional execution surface during dependency operations. No provided signal shows these scripts are harmful, so this is a modest caution rather than a severe finding.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms Version 8.7.* | — | — |
helhum/typo3-console Version ^4.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.