This release is usable but merits caution rather than being considered a highly mature dependency. It is a stable v2.0.0 release with an explicit GPL-2.0-or-later license, a complete 34-file package tree, no install-time lifecycle scripts, and a repository that matches and documents the package. The repository is organization-backed, active enough to have been pushed with the release, and has a recent merged pull request, but its longer-term maintenance evidence is thin: there have been only 9 releases since 2023, just 1 release in the last 12 months, and no commits or active maintainers in the preceding 3 months. The absence of tests, a changelog, security policy, and security scanning reduces transparency and assurance, although the package's small TYPO3 extension scope and lack of dangerous workflows limit the severity of those gaps.
65%
Total Score
83
100
81
83
A substantive README and contributing document are present, but neither the artifact nor repository contains tests or a changelog. For a small extension this is a genuine transparency and maintenance gap, though GitHub Releases provide some compensating release communication.
The package has existed for about 3 years 7 months with 9 releases, but only 1 release in the last 12 months indicates relatively limited recent release activity.
The repository recorded zero commits and zero active maintainers in the last 3 months. Although the release-time push and recent merged pull request provide some compensating evidence, the recent maintenance capacity remains thin.
Composer build tooling is present, but no security scanning tools are configured. The missing scanning lowers assurance but is not by itself a severe dependency risk.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a transparency gap for a package consumed in production.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.