The repository includes tests, a changelog, security scanning, and a clear GPL-2.0+ license. Its small maintainer base and lack of commit activity in the last three months warrant checking future support before adopting.
72%
Total Score
50
100
100
67
A post-autoload-dump install-time script is present. This is a modest supply-chain and installation-complexity concern, though the signal does not show a dangerous script.
Only one account has registry publishing access. The linked repository is user-owned rather than organization-backed, so this leaves a thin publishing and support base.
The registry namespace and repository owner match, but the owner is an individual rather than an organization, so there is no organizational backing to offset the small maintainer base.
The repository recorded zero commits and zero active maintainers in the last three months. Although a recent registry release exists, current source activity is not demonstrated.
There are four open issues but no issues or pull requests were opened or closed in the last month, providing little evidence of active community support.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^11.5 | — | — |
typo3/cms-fluid Version ^11.5 | — | — |
dwenzel/t3extension-tools Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.