Healthy and reasonable to use, with some maintenance caveats. It has a current stable release, recent publishing activity, a matching repository, and organization backing, but recent development is concentrated in one contributor and the repository lacks security policy and explicit workflow permissions.
78%
Total Score
75
100
89
67
All recent commits came from one contributor, creating a concentrated maintenance dependency. Organization backing partly compensates because maintenance can potentially be handed off internally.
One commit was made in the last 3 months by one active maintainer, showing some recent work but only a thin maintenance signal.
The repository has no stars or forks and only 2 watchers, so there is little external adoption evidence; this is a supporting weakness rather than a decisive concern for a small extension.
Composer is used as a build tool, but no repository security scanning tool was detected. The missing scanning is a modest transparency gap, not evidence that the package is unsafe.
The repository has no published security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4.0 || ^14.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.