Usable with caveats: the package is actively released, backed by an organization, and has a recent stable release with tests and release notes. Maintenance is concentrated in one recent contributor, the package has no README, and its install-time script and missing security policy reduce transparency.
72%
Total Score
67
94
75
The package defines a post-autoload-dump install-time script. Such scripts add execution surface during installation, and no provided signal explains why it is needed or what it does.
The artifact and repository include tests, and this exact version has GitHub release notes describing TYPO3 14 compatibility. The missing package README is a real usability and transparency gap for a TYPO3 extension, but the release notes and tests partly compensate.
All two recent commits came from one contributor, giving the project a concentrated bus factor. The organization-owned repository provides some ability to hand maintenance off, so this is a caution rather than a severe abandonment risk.
The repository received two commits in the last three months from one active maintainer, showing recent activity but a relatively low maintenance volume.
No repository security policy was found. This limits transparency about vulnerability reporting and response, although security scanning is present and partly offsets the gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 || ^13.4 || ^14.3 | — | — |
digital-marketing-framework/distributor-pardot Version ^3.0 | — | — |
digital-marketing-framework/typo3-distributor-request Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.