Healthy and actively maintained, with frequent stable releases, a complete tested package, and a matching source repository. The main caveat is that all recent commits come from one contributor and the repository has no security policy or security scanning.
82%
Total Score
50
100
94
90
The registry namespace and repository owner align, but the owner is an individual rather than an organization. This supports package identity while not providing organizational maintenance redundancy.
One contributor made 100% of the 26 recent commits. Because the repository is owned by an individual rather than an organization, this creates a genuine continuity risk if that maintainer becomes unavailable.
The repository had 26 commits in the last three months, showing active work, but all were made by one active maintainer. Activity is strong while contributor depth is limited.
The repository uses Composer but reports no security-scanning tools. Build tooling is present, though the lack of automated security scanning leaves a transparency gap.
The repository has no security policy. For a package that fetches and renders external RSS/Atom content, the absence of a documented vulnerability-reporting process is a modest transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 || ^14.3 | — | — |
typo3/cms-fluid Version ^13.4 || ^14.3 | — | — |
typo3/cms-extbase Version ^13.4 || ^14.3 | — | — |
typo3/html-sanitizer Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.