Documentation is present, the dependency list is small, and the source repository remains available. The registry marks this package as abandoned, while recent repository activity has stopped and its license files conflict with the declared license.
22%
Total Score
50
100
75
50
Packagist marks the entire package as abandoned, with no usable replacement identified beyond a name variant. This is a severe adoption risk for a new dependency.
The manifest declares GPL-2.0-or-later, but the artifact also contains a detected MIT license file. This mismatch creates legal ambiguity for consumers.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. That weakens confidence in ongoing maintenance despite recent registry releases.
The repository has no security policy. This is a transparency and maintenance gap, although it is less significant than the package-level abandonment status.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 || ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.