The repository has 27 commits in three months, two active contributors, tests, release notes, and a current push. One maintainer, no security policy, and no security scanning leave modest resilience and transparency gaps.
82%
Total Score
75
100
83
88
The repository is owned by an individual user rather than an organization, so the concentrated contribution pattern and single registry maintainer represent genuine continuity risk.
The package is only 284 days old and has two releases, with a median interval of about 261 days. This is limited release history, but the latest release is recent and repository activity is strong.
Two contributors were active, but one produced about 81% of the 27 recent commits. The second contributor provides some continuity, while ownership remains concentrated.
The repository has zero stars and forks and one watcher, so there is little external adoption evidence. This is supporting evidence only and is outweighed by recent maintenance.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest process gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 || ^14.3 | — | — |
typo3/cms-fluid Version ^13.4 || ^14.3 | — | — |
typo3/cms-backend Version ^13.4 || ^14.3 | — | — |
typo3/cms-extbase Version ^13.4 || ^14.3 | — | — |
typo3/cms-install Version ^13.4 || ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.