This release appears generally suitable to depend on: it is not deprecated or archived, has a recent release, a meaningful release history, repository-backed documentation and tests, an explicit license, security policy, and no install-time lifecycle scripts or dangerous workflow patterns. The main concerns are that the project remains below a stable major version, all recent commits come from one maintainer, repository activity is modest, and the CI workflow does not declare top-level token permissions or use security-scanning tooling. These are manageable maintenance and transparency risks rather than evidence that the package is unfit for use.
78%
Total Score
60
100
88
90
Only one registry account has publish access. Because project backing identifies an individual user rather than an organization, this creates a genuine continuity risk, though repository activity shows that the maintainer is currently active.
The linked repository is owned by a User rather than an organization, so there is no organizational backing to offset the single-maintainer concentration.
All 4 recent commits came from one contributor, giving the project a complete single-contributor concentration and increasing continuity risk; the individual ownership context provides no organizational handoff evidence.
There are 4 open issues and no issue or pull-request activity in the last month. The absence of recent resolution activity is a modest maintenance concern, but it is not by itself evidence of abandonment.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a hygiene gap, although other repository security signals are favorable.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 || ^14.3 | — | — |
typo3/cms-scheduler Version ^13.4 || ^14.3 | — | — |
promphp/prometheus_client_php Version ^2.14 | — | — |
promphp/prometheus_push_gateway_php Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.