Risky to adopt unless you specifically need this legacy TYPO3 extension. It has clear licensing, a matching repository, and a stable published release, but there has been no release or repository activity for nearly nine years and the repository has no active issue resolution.
48%
Total Score
25
100
75
50
The package has only two releases, with the latest published on 2017-10-20 and no releases in the last 12 months. Nearly nine years without a release is a strong abandonment and compatibility risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the nearly nine-year gap since the last release. This provides no evidence of ongoing maintenance.
There are two open issues but no new or closed issues and no pull requests in the last month, so reported problems show no recent resolution activity.
The repository uses Composer, which supports reproducible package management, but it has no security scanning tools. This is a modest hygiene gap rather than evidence that the package is unsafe.
The linked repository is not marked archived, which avoids an explicit abandonment signal. However, its last push was on 2017-10-20, so the non-archived status does not compensate for the observed inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version >=7.6,<9 | — | — |
georgringer/news Version >3.2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.