It includes a README, changelog, release notes, and a declared GPL license. The repository is not archived and has no install scripts, but its small user base and absent security tooling limit confidence.
43%
Total Score
25
75
50
Only two releases are recorded, with the latest published about eight years ago and none in the last 12 months. This is strong evidence of abandonment risk for a package consumers may need to keep compatible with current TYPO3 versions.
The repository had no commits or active maintainers in the last three months, and its last push was about five years ago. The repository is not archived, but that does not offset the lack of observed maintenance.
There were no new or closed issues or pull requests in the last month, while three issues remain open. This reinforces the evidence of an inactive project.
Composer is used for builds, but no security-scanning tooling was detected. The missing scanning is a hygiene gap rather than evidence of unsafe code by itself.
The repository has no security policy, leaving no documented path for reporting vulnerabilities. This is a transparency gap, although it is less significant than the package's prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version >=6.2,<8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.