Integration tests are present and the package has a small runtime dependency set. Only one release appeared in the last year, repository commits stopped during the last three months, and the linked repository does not clearly mention the package.
55%
Total Score
50
75
83
The package has 23 releases over about three years, but only one release in the last 12 months; that recent slowdown weakens confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, despite a recent package release; this is direct evidence of currently stalled source activity.
The repository name does not match the package name and the collected README field does not show a package mention, so the source-package relationship is not clearly established.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The assessed version is marked stable, but every recent release is classified as a prerelease, which makes the release channel less predictable.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ~10.4.0 | — | — |
madj2k/t3-core-extended Version ~10.4.0 || ~11.5.0 || ~12.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.