The package has clear documentation, a matching repository, and a recent release, while the organization backing provides some continuity. Its license files and declaration disagree, the repository has only one recent contributor, and both workflow actions are unpinned.
68%
Total Score
67
100
88
67
The manifest declares GPL-2.0-or-later, while the artifact license file and repository license are detected as GPL-3.0. The release is licensed, but the mismatch creates a material compatibility and transparency concern.
All recent commits came from one contributor, creating a narrow operational base. Organization ownership offers some handoff capacity, so this is a caution rather than a severe risk.
There was one commit in the last 3 months, so the project is not inactive, but the observed maintenance activity is limited. The recent release provides some compensation.
Composer build tooling is present, but no security-scanning tooling was detected. The absence lowers repository hygiene confidence without showing that the release is unsafe.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, not evidence of a security defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4.0 | — | — |
typo3/cms-fluid Version ^13.4.0 | — | — |
typo3/cms-frontend Version ^13.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.