Recent maintenance is quiet, with no commits in three months and no releases in the last 12 months. The package is documented and backed by an organization, but its two workflow actions are unpinned and the repository has no security policy.
58%
Total Score
67
69
50
The artifact declares GPL-2.0-or-later and includes a license file, while the detected text is GPL-2.0. The release is licensed, but the scope mismatch should be clarified before redistribution.
The package has 11 releases since June 2019, but none in the last 12 months; the latest release was about 18 months ago. This is a meaningful maintenance concern for a framework extension.
There were zero commits and zero active maintainers in the last three months. That is the clearest maintenance concern in the available evidence.
The repository has four open issues and one open pull request, but no new or closed issues and no merged pull requests in the last month. This suggests limited current project activity.
The repository has three stars, nine forks, and eight watchers. Low popularity is only supporting evidence, but it indicates a small public user base and limited external visibility.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.