The release has a README, tests, and detailed notes for its database and encryption migration. Its source and registry metadata otherwise provide no credible basis for ongoing maintenance, so pinning it would leave substantial upgrade and support risk.
12%
Total Score
0
50
Packagist marks the entire package as abandoned, with no replacement package supplied. Package-level deprecation is a severe adoption warning rather than a release-specific notice.
The package has 21 releases and a historical median interval of about 33 days, but it has had no releases in the last 12 months and was last released in February 2019. The earlier cadence does not compensate for the prolonged halt.
The repository recorded zero commits and zero active maintainers during the last three months. Combined with the archived state, this shows maintenance has stopped rather than merely slowed.
The linked Ecodev/newsletter repository is archived, which indicates the source project is no longer maintained. Its last push was in April 2019, about seven years ago.
| Title | Versions | Severity |
|---|---|---|
CVE-2021-38302 ecodev/newsletter is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 4.0.0. | 0.0.0 - 4.0.0 | Low |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^7.6 || ^8.7 | — | — |
typo3/cms-fluid Version ^7.6 || ^8.7 | — | — |
typo3/cms-backend Version ^7.6 || ^8.7 | — | — |
typo3/cms-extbase Version ^7.6 || ^8.7 | — | — |
typo3/cms-scheduler Version ^7.6 || ^8.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.