The package includes tests and a changelog, and its organization-owned repository is not archived. A missing security policy and absent recent commit activity reduce confidence in ongoing maintenance.
68%
Total Score
75
100
100
67
A post-autoload-dump install-time script is present. This adds execution during installation and warrants review, but the signal alone does not establish a severe dependency risk.
The repository had zero commits and zero active maintainers in the past three months, which conflicts with the recent registry release cadence and raises concern about sustained source maintenance.
No repository security policy was found, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 || ^13.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.