The package is compact and has no install-time scripts, limiting adoption complexity. Its last release and repository activity were in October 2016, while the declared GPL-3.0+ conflicts with the artifact's MIT license.
38%
Total Score
0
100
75
83
Only two releases were published, both in October 2016, with no release in more than 9 years. This is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with activity ending in October 2016. The small project scope provides limited compensation.
The manifest declares GPL-3.0+, but the artifact license file is detected as MIT; although a license file exists, the mismatch creates meaningful uncertainty for consumers.
Composer is used for the build, but no security scanning tools are configured. For this small, inactive package that is a minor transparency gap rather than a primary adoption blocker.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This adds a modest transparency concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/neos Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.