The repository includes tests and extensive documentation, and the package declares a GPL license. Its two releases were published in July 2022, with no later release or repository activity, making long-term support uncertain.
45%
Total Score
50
72
67
The package has only two releases, both from July 2022, and none in the last four years. This is strong evidence of abandonment risk, although the repository is not archived.
The package runs a post-autoload-dump lifecycle script, which adds install-time behavior that consumers should understand. The signal does not show that the script is harmful, so this is a limited supply-chain hygiene concern.
The repository is owned by an individual rather than an organization, and no organizational backing is shown. That leaves a relatively thin apparent support base, consistent with the limited release and popularity history.
The repository has zero stars and forks and only one watcher, indicating little visible adoption or community support. Popularity is supporting evidence, so this modestly reinforces the maintenance concern rather than deciding it alone.
Composer is used for builds, but no security scanning tools are configured. This reduces transparency around automated security checks, while the absence of scanning alone is not evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^11.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.