Usable with caveats: it is licensed, documented, tested, and not deprecated or archived, but the last release and repository activity were over six years ago. Depend on it only if its older TYPO3 compatibility is acceptable and you can maintain it yourself.
56%
Total Score
50
100
88
88
There were zero commits and zero active maintainers in the past three months, following the last repository push more than six years ago. This is the strongest evidence of abandonment risk.
The latest release was published on April 22, 2020, with no releases in the past 12 months. The package has eight releases over roughly 10 years, showing an established history but prolonged release inactivity.
There were no new or closed issues or pull requests in the past month, and eight issues remain open. That indicates little visible current support or issue resolution.
Composer is used for builds, giving the project standard dependency tooling. No security-scanning tool is present, which is a hygiene gap but not by itself evidence that the package is unsafe to depend on.
The repository has no security policy. For an extension affecting backend users and roles, this reduces vulnerability-reporting transparency, though the available source, tests, and documentation provide some compensating visibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^8.7 || ^9.5 || ^10.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.