The repository matches the package, and 59 commits in the last three months show active work. Missing tests, a security policy, and a broader maintainer base limit confidence.
68%
Total Score
67
100
83
50
The artifact has no README, tests, or changelog, while the repository includes dedicated Documentation files. The documentation partly offsets the missing package README, but the lack of repository tests and release history reduces maturity evidence.
The repository is owned by a user account rather than an organization, so there is no organizational handoff capacity to offset the single-contributor concentration.
Only two releases have been published, with the latest about 94 days after the first. This is a young project, although recent repository activity provides some compensation.
One contributor made all 59 commits in the last three months, leaving the project dependent on a single maintainer and creating a meaningful continuity risk.
Composer is used for builds, but no security scanning tool is reported. The missing scanning is a modest transparency and maintenance gap rather than evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.