The package has clear licensing, a matching repository, a useful README, and a small dependency set. Its very limited recent activity and missing security policy make long-term maintenance less certain.
60%
Total Score
50
100
88
75
The registry namespace and repository are owned by the same individual, which is consistent with a directly maintained small project but provides limited organizational redundancy.
The package has existed since January 2020 and has seven releases, but it has had no release in about 22 months. That weakens confidence that the project is actively maintained.
There were no commits and no active maintainers in the last three months. Combined with the long release gap, this is a meaningful maintenance concern.
There is one open issue and no issue or pull-request activity in the last month, providing little evidence of ongoing project attention.
Composer is used for builds, but no security scanning tooling was detected. For a small package this is a hygiene gap rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^10 || ^11 || ^12 || ^13.4 | — | — |
nadar/php-composer-reader Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.