Its clear README, small dependency set, and organization backing make adoption easier. The repository is active but lightly worked, and it has no security policy.
70%
Total Score
67
100
88
67
A post-autoload-dump lifecycle script runs during installation, adding some execution-time supply-chain exposure even though no evidence shows it is harmful.
All one recent commit came from a single contributor, creating concentration risk; organization ownership provides some ability to hand maintenance to others.
There was one commit in the last 3 months, so maintenance is present but light and provides limited evidence of sustained development capacity.
The repository uses Composer, but no security scanning tools were detected, leaving security hygiene less independently verified.
The repository has no security policy, reducing transparency about how users should report vulnerabilities and how security issues are handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.