The focused artifact has a clear README, simple dependencies, no install-time scripts, and a repository that matches the package. It lacks a security policy and scanning, leaving little evidence of ongoing oversight.
32%
Total Score
0
100
78
75
This is the package's only release, published about 7 years ago, with no releases in the last 12 months. That strongly raises abandonment and compatibility risk.
The repository recorded zero commits and zero active maintainers over the last 3 months, consistent with the package having received no development since April 2019.
The repository has only 3 stars and no forks, providing little evidence of a broad user or contributor community. Low popularity is supporting caution rather than proof of poor quality.
Composer is used for the build, but the repository has no security scanning tools. That weakens ongoing security oversight, although it is secondary to the maintenance evidence.
The repository has no security policy, leaving no stated process for reporting or handling vulnerabilities. This is a transparency and maintenance concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^8.7|^9|dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.