The package includes tests, installation guidance, and a small runtime dependency set. Its missing security policy and security scanning reduce transparency, while the repository’s limited public footprint provides little additional assurance.
63%
Total Score
50
100
80
75
The package has 18 releases since April 2019, but none in the last 12 months; the latest release was published in March 2025. This indicates a meaningful maintenance slowdown, although the release history is established.
The repository recorded no commits and no active maintainers in the last three months. That supports the release-history concern and leaves current maintenance capacity unclear.
Composer build tooling is present, but no security-scanning tools were detected. The lack of scanning modestly lowers assurance and is partly consistent with the absent security policy.
The repository has no published security policy. This is a transparency gap for a package that handles legal-document generation, though it does not by itself show unsafe behavior.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4.2 || ^13.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.