The README is detailed, licensing is clear, repository tests are present, and the package uses no install-time scripts. A missing security policy and unpinned workflow actions leave useful maintenance and build safeguards weaker.
61%
Total Score
50
100
86
67
The repository is owned by an individual user rather than an organization, so the single registry maintainer does not have organizational backing to offset the limited activity evidence. This leaves a relatively thin apparent support structure.
The package has 29 releases and a historically short median interval of about 12 days, but it has had no releases in the last 12 months; the latest release was about 16 months ago. This indicates materially slowed maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months, despite being unarchived and having been pushed more recently. The current lack of development activity raises abandonment risk.
The repository has 18 open issues and 2 open pull requests, but no new or closed issues and no new or merged pull requests in the last month. This suggests limited recent project responsiveness.
The project uses Composer, which fits the package ecosystem, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/intl Version ^5 || ^6 | — | — |
typo3/cms-core Version ^11.5 || ^12.4 | — | — |
typo3/cms-lang Version ^11.5 || ^12.4 | — | — |
typo3/cms-backend Version ^11.5 || ^12.4 | — | — |
typo3/cms-extbase Version ^11.5 || ^12.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.