The package has tests, a clear license, and organization backing. Its last release and repository push were nearly two years ago, with no commits in the past three months and no security policy.
58%
Total Score
50
100
88
50
There were no commits and no active maintainers in the past three months. Combined with the last push being nearly two years ago, this is the clearest sign that maintenance may have stalled.
The package runs a post-autoload-dump lifecycle script. This adds some installation complexity, but the signal provides no evidence that the script is unsafe or unusually broad.
The package has five releases over about four years, but none in the last 12 months; the latest release was nearly two years ago. This indicates slowing maintenance, though the release history is established rather than abandoned outright.
Composer is used as the build tool, providing ordinary project tooling, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance concern rather than proof of a defect.
The repository has no security policy. For a package that provides frontend and backend consent utilities, this leaves vulnerability-reporting expectations unclear.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^11.5 || ^12.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.