The repository is modest in size, with focused dependencies and clear package ownership. Its README and release notes give integrators useful context; confirm the applicable GPL terms before distributing it.
61%
Total Score
67
100
88
75
The manifest declares GPL-2.0+, while the artifact license file is identified as GPL-3.0; the presence of license files is positive, but the mismatch needs clarification.
There were no commits and no active maintainers in the last 3 months, indicating a recent maintenance pause and increasing abandonment risk.
The repository has two open issues and one open pull request, with no issues or pull requests closed in the last month; this suggests limited current responsiveness.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest security-process gap.
The repository has no published security policy, reducing clarity about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^11.5 || ^12.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.