Bridges the TYPO3 MCP Server and Content Planner extensions, exposing content-planner status, assignee and comment workflows as MCP tools for AI assistants.
68%
Total Score
60
100
83
80
A post-install-cmd lifecycle script introduces install-time execution that should be reviewed before depending on the package, even though no dangerous behavior is shown by this signal alone.
Only one registry account has publish access. This is a real publishing continuity risk for a user-owned project, with repository activity showing the same concentration rather than a broader maintainer base.
The repository is owned by an individual user rather than an organization, so the single-maintainer and single-contributor concentration is not compensated by visible organizational backing.
The package is only 26 days old with three releases and a median interval of about 13 days, showing active early development but limited evidence of long-term maintenance.
One contributor made 100% of the 48 recent commits, creating a severe concentration risk for continuity; the repository is user-owned, so no organization-level handoff capacity is evidenced.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 || ^14.3 | — | — |
hn/typo3-mcp-server Version ^0.5.0 || ^0.6.0 | — | — |
logiscape/mcp-sdk-php Version ^1.2 || ^2.0 | — | — |
xima/xima-typo3-content-planner Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.