The package has clear documentation, repository tests, a matching organizational source repository, and a current release supporting TYPO3 v14. Recent development is quiet, and workflow references are unpinned; the high-confidence template-injection findings remain hygiene concerns because no untrusted trigger or checkout is reported.
64%
Total Score
67
100
83
83
The package has existed since 2018 with 19 releases, but only one release appeared in the last 12 months and the median interval is about 147 days. This indicates a mature but relatively slow release cadence.
The repository recorded zero commits and zero active maintainers in the last three months. This is the clearest abandonment concern, although the recent release shows the project has not stopped entirely.
There are four open issues and one new issue in the last month, with no pull requests merged; this suggests limited recent project activity but is not, by itself, evidence of abandonment.
The repository has only 3 stars and 9 forks, so community adoption appears modest. Popularity is supporting evidence rather than a decisive health measure, especially for a focused extension.
Composer build tooling is present, but no security scanning tool was detected. The missing scanner is a moderate transparency gap rather than a direct dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.