The repository has no commits or releases for more than three years, and its only registry maintainer is an individual account. All 11 workflow actions are unpinned, while the repository has no security policy.
43%
Total Score
25
50
83
75
The package has 133 releases, but none in the last 12 months and its latest release was more than three years ago. The historically frequent releases show past activity, but not current maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the latest release. This is strong evidence that maintenance has stopped or substantially slowed.
The package declares 13 runtime dependencies, including many development and quality tools, creating a relatively broad dependency surface for a helper package. No compensating signal shows that this surface is intentionally minimized.
One registry account has publish access, and project_backing identifies it as an individually owned repository rather than organization-backed. A single maintainer increases continuity risk when recent activity is absent.
No security policy was found in the repository. This weakens vulnerability-reporting transparency, although it is less significant than the clear maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/tailor Version ^1.5.0 | — | — |
sebastian/phpcpd Version ^6.0.3 | — | — |
ssch/typo3-rector Version ^1.2.2 | — | — |
micheh/phpcs-gitlab Version ^1.1.0 | — | — |
michielroos/typo3scan Version ^1.7.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.