The repository is small and has no tests, changelog, security policy, or security scanning. It is not archived or deprecated, and its stable version has a matching source tree, but the license mismatch should be resolved before adoption.
58%
Total Score
50
100
75
83
The manifest declares GPL-2.0-or-later, while the artifact license file is detected as MIT; although a license file exists, this mismatch creates a material licensing ambiguity.
The artifact has no README, tests, or changelog, and the repository also reports no tests or changelog. The missing tests and changelog are normal packaging practice here, but the missing README modestly reduces consumer transparency.
The package has only two releases and none in the last 12 months; its latest release was in January 2025, indicating a long period without registry updates.
The repository had zero commits and zero active maintainers in the last three months, which weakens evidence of ongoing maintenance.
Composer is used for the build, but no security scanning tools are present, leaving an avoidable repository hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-backend Version ^10 || ^11 || ^12 || ^13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.