This is a healthy, actively maintained release with a strong maintenance record: 31 releases over roughly 4 years, 10 releases in the last 12 months, a recent release, and 58 commits from two active contributors in the last 3 months. The repository is not archived, the package is not deprecated, the artifact is well documented and licensed, and the repository contains tests, changelog material, and build tooling. The main reservations are the low popularity, a concentrated contributor base, absence of a security policy and automated security scanning, and an undelimited GitHub Actions token-permission configuration; these are meaningful hygiene gaps but do not outweigh the demonstrated release and commit activity.
87%
Total Score
70
100
89
80
Only one registry account has publish access, which is a modest publishing continuity concern. However, repository activity shows two active contributors, so the observed maintenance base is stronger than the registry access list alone suggests.
The repository is owned by an individual user rather than an organization, so there is no organization-level maintenance handoff evidence. This modestly increases dependence on the small observed contributor base.
Two contributors are active, but the leading contributor accounts for about 71% of recent commits. This is a concentration risk, though the second contributor's 17 commits provides meaningful compensation.
The repository has 7 stars, 15 forks, and 4 watchers. This is limited adoption evidence, but popularity is supporting evidence only and does not outweigh the strong maintenance signals.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning coverage is a security-hygiene gap, not evidence of abandonment by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 || ^14.3 | — | — |
onelogin/php-saml Version >=4.3.1 <5.0 | — | — |
typo3/cms-backend Version ^13.4 || ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.