It includes a README, license, documentation, and only one runtime dependency. The repository is not archived, but it has no security policy or scanning.
18%
Total Score
75
100
56
83
The registry marks the entire package as abandoned, with no replacement named. This is a direct warning that the release should not be adopted for new dependencies.
The package has only three releases, all effectively from March 2016, and none in the last 12 months. That long period without a release strongly indicates abandonment risk.
The artifact and repository contain a license, but the declared GPL-2.0+ differs from the detected GPL-2.0 text. The release is licensed, though the mismatch warrants checking the intended licensing terms.
The repository has one open issue and no new or closed issues or pull requests in the last month. This provides no evidence of active support.
Composer is used for builds, but no security scanning tool is configured. The missing scanning is a hygiene gap, not a standalone reason to reject the package.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.