The package has recent releases, seven commits in three months, and four active contributors. Its declared GPL-2.0+ conflicts with the GPL-3.0 license file, while the repository lacks a security policy and pins none of its one workflow actions.
82%
Total Score
83
100
81
75
The artifact includes a license file, but it identifies GPL-3.0 while the manifest declares GPL-2.0+, creating an unresolved licensing mismatch for consumers.
The repository is owned by the named publisher account, but the owner type is an individual user rather than an organization; this provides limited formal backing evidence.
The repository has one star and no forks, indicating limited adoption evidence. Popularity is supporting evidence only, so this does not outweigh the active maintenance signals.
Composer is used for builds, but no security scanning tool was detected; the missing scanning is a modest transparency and hygiene gap.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for users and maintainers.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12 || ^13 || ^14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.