The package has a focused file tree, a declared GPL license, and only one runtime dependency. Documentation is minimal, while repository security practices and community activity provide little evidence of ongoing support.
38%
Total Score
75
100
63
83
The package has had only two releases, both in May 2018, with no releases in the last 12 months and a package age of over eight years. This is strong evidence of abandonment risk for a dependency.
The artifact includes a changelog and a README, and the absence of tests is normal packaging practice. The README is only 21 characters long, so consumer documentation is notably thin.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This is consistent with a very quiet project and offers no evidence of active maintenance.
The repository has zero stars and forks and only three watchers. Popularity is supporting evidence rather than a verdict, but these numbers provide little outside evidence of active adoption.
Composer is used for builds, which fits the package ecosystem, but no security scanning tools are configured. The missing scanning is a hygiene gap rather than a severe risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version >=6.2.12,<8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.