Documentation, tests, and a declared GPL-2.0+ license improve transparency, while the small dependency set is straightforward. The absent security policy adds a minor concern; use a maintained TYPO3 extension instead.
18%
Total Score
50
60
75
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on this release.
Only two releases exist, and the latest was published in January 2018; there have been no releases in roughly eight years. That indicates severe abandonment risk.
The repository recorded zero commits and zero active maintainers during the measured three-month period, consistent with the package's long period without releases.
There are three open issues but no new or closed issues and no pull-request activity in the measured month, showing that reported maintenance needs are not being addressed.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is secondary to the stronger abandonment signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^6.2 || ^7.6 || ^8.7 | — | — |
typo3/cms-lang Version ^6.2 || ^7.6 || ^8.7 | — | — |
typo3/cms-backend Version ^6.2 || ^7.6 || ^8.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.