This is a healthy, established release with a track record since 2017, 25 releases, a stable current version, recent release activity, active repository work, clear licensing, a matching organization-owned repository, and comprehensive source documentation and tests. The main concerns are that all 23 commits in the last 3 months came from one contributor, the repository has no security policy or security-scanning tooling, and its workflow does not declare top-level token permissions. These are meaningful transparency and resilience gaps, but they are outweighed by active maintenance, recent merged pull requests, repository-backed tests, and the absence of deprecation or archival indicators.
82%
Total Score
90
100
89
80
Only one contributor made all 23 commits in the last 3 months, creating a real continuity risk. The organization-owned repository provides some potential for handoff, but no second active contributor is evidenced.
The repository has 0 stars, 1 fork, and 2 watchers, showing limited public adoption. Popularity is supporting evidence only, so this modest visibility is a caution rather than a decisive health problem.
Composer build tooling is present, but no security-scanning tools are configured. The missing scanning is a security-hygiene gap, though it does not indicate abandonment on its own.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
The CI workflow lacks top-level token permissions, so its effective permissions are less explicit than recommended. No workflow with explicit top-level write permissions was found, limiting the severity of this gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 | — | — |
typo3/cms-filelist Version ^13.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.