The package has a clear README, a narrow dependency surface, and no install-time scripts. Its small, focused source tree is easy to inspect, but provides limited evidence of ongoing support or security process.
38%
Total Score
33
100
71
83
The latest release was published in March 2019, and there have been no releases in the last 12 months. This is strong abandonment evidence for a dependency, although the package is not marked deprecated.
There were zero commits and zero active maintainers in the last three months. Combined with the old last release, this indicates that support and compatibility work may have stopped.
The repository is owned by an individual rather than an organization, so there is no visible organizational backing to compensate for the lack of recent activity.
The repository has one open issue and no new or closed issues or pull requests in the last month. This is limited evidence of project activity and adds to the maintenance concern.
Composer is used for the build, which fits the package ecosystem, but no security scanning tools are present. This is a process gap rather than a standalone reason to reject the package.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-fluid Version ^8|^9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.