The package has a clear license, a focused six-file artifact, and no install-time scripts. Its README documents installation and usage, while the single-maintainer project provides limited evidence of broader support.
58%
Total Score
50
100
75
75
Only two releases exist, with none in the last 12 months; the latest release was over three years ago. This is the strongest evidence of reduced maintenance despite the regular one-month interval between the initial releases.
One registry maintainer is responsible for publishing the package, leaving little visible redundancy if that maintainer becomes unavailable. The linked repository and package ownership match, so this is a modest resilience concern rather than evidence of abandonment by itself.
The repository recorded no commits and no active maintainers in the last three months. The repository is not archived, but this still weakens confidence that compatibility issues will be addressed promptly.
The repository has no security policy. For a small focused extension this is a transparency gap, although it does not by itself show that the package is unsafe to depend on.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^10.4 || ^11.5 || ^12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.