The package has a long release history, a complete artifact, an explicit GPL license, and no install-time scripts. Use liquidlight/typo3-form-to-database instead, as Packagist marks this package abandoned.
15%
Total Score
75
100
Packagist marks the entire package as abandoned and provides liquidlight/typo3-form-to-database as a replacement. Package-level abandonment is a severe dependency risk even though the release history is substantial.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-10316 lavitto/typo3-form-to-database is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.2.5, 3.0.0 - 3.2.2, 4.0.0 - 4.2.3 and 5.0.0 - 5.0.2. | 0.0.0 - 2.2.53.0.0 - 3.2.24.0.0 - 4.2.3 +1 more | Low |
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4.20 | — | — |
typo3/cms-form Version ^13.4.20 | — | — |
typo3/cms-fluid Version ^13.4.20 | — | — |
typo3/cms-backend Version ^13.4.20 | — | — |
typo3/cms-extbase Version ^13.4.20 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.