Maintenance has slowed, with no commits in three months and no releases in the last year. The package remains documented, licensed, stable, and linked to an active, non-archived source repository, but it is best adopted with version compatibility checked.
62%
Total Score
50
100
88
75
The package has existed for about 7 years with four releases, but none in the last 12 months and a median release interval of about 17 months, indicating slow maintenance rather than abandonment by itself.
There were zero commits and zero active maintainers in the last three months, a concrete sign that maintenance has currently slowed.
The repository has seven open issues and four open pull requests, with no issues or pull requests opened or merged in the last month; this suggests limited current responsiveness.
The repository uses Composer build tooling, but no security scanning tools were detected, leaving a modest repository-hygiene gap.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities, though this is not severe enough to make the release unfit on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^11.5 || ^12.4 | — | — |
georgringer/news Version ^11 || ^12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.