This is a generally healthy and supportable release: it is stable, not deprecated or archived, has a recent release cadence, an organization-owned repository, clear package/repository alignment, licensing, documentation, tests, a changelog, and a minimal runtime dependency profile. The main concerns are that recent repository activity is limited to two commits from one contributor, the repository has very little community traction, and no security policy or security-scanning tool was observed. These issues warrant monitoring but do not outweigh the evidence of ongoing maintenance and release activity.
82%
Total Score
80
100
89
90
All 2 recent commits came from one contributor, creating a concentrated contributor base. The organization-owned repository provides some handoff capacity, but no second active contributor is evidenced.
The repository recorded 2 commits in the last 3 months, showing some recent activity but at a low rate; the limited volume warrants monitoring rather than indicating abandonment by itself.
The repository has only 1 star, 0 forks, and 4 watchers. Low popularity is supporting caution about external adoption and review, but it is not decisive for a small, focused extension.
Composer build tooling is present, but no security-scanning tool was observed. The missing scanning coverage is a transparency and preventive-hygiene gap, not evidence of maliciousness.
No repository security policy was found, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 || ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.