There have been no commits in the last three months, and only one release in the past year, so ongoing maintenance is limited. The package is licensed, tied to a matching organization repository, and has no deprecation or workflow-audit findings.
60%
Total Score
75
83
50
The package has 28 releases over about four years, but only one release in the last 12 months. That supports an established history while indicating a currently slow release cadence.
There were zero commits and zero active maintainers in the last three months. This is the clearest maintenance concern, although the recent repository push and release history provide limited counterevidence.
The repository has zero stars, one fork, and two watchers, showing a very small user footprint. Popularity is supporting evidence rather than a decisive health measure, so this is a minor concern.
Composer is used for the build, but no security-scanning tools are configured. The missing scanning is a hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This lowers transparency but is not severe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4.0 | — | — |
typo3/cms-fluid Version ^13.4.0 | — | — |
typo3/cms-frontend Version ^13.4.0 | — | — |
typo3/cms-fluid-styled-content Version ^13.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.