The package has a declared GPL-2.0-or-later license and a documented TYPO3-oriented file tree. Composer is used for builds, but no repository security scanning is reported.
42%
Total Score
50
75
50
A post-autoload-dump lifecycle script runs during installation. Composer lifecycle scripts are not inherently unsafe, but they add installation-time behavior that should be understood before adoption.
The repository is owned by an individual account rather than an organization, so the single-person project backing offers limited continuity if the maintainer stops work.
Only three releases were published, all clustered in February 2022, with no release in more than four years. That is strong evidence of an unmaintained package.
There were no commits and no active maintainers in the last three months, with the last repository push more than four years ago. This is the strongest maintenance concern for the release.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of an active user community.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^10.4 || ^11.5 | — | — |
mcstreetguy/composer-parser Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.