Its clear README, matching source repository, and explicit testing-only scope make the small extension easy to understand. The single-maintainer project has no recent development activity or security policy, limiting confidence in future compatibility and response capacity.
56%
Total Score
50
100
71
75
The repository is owned by an individual account rather than an organization, so the single-person publishing and maintenance model carries less backing capacity.
Only two releases exist, both published in February 2025, with no release in the last 12 months despite the package being about 586 days old. This is meaningful abandonment risk for a dependency tied to TYPO3 versions.
There were zero commits and zero active maintainers in the last three months. Combined with the old last push, this indicates no observed ongoing maintenance.
Composer is used for the build, which fits the package ecosystem. No security scanning tools were detected, leaving a modest repository-hygiene gap.
The linked repository is not archived, but its last push was on February 8, 2025. The active repository status is positive while the old push date reinforces the maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 || ^13.4 | — | — |
typo3/cms-backend Version ^12.4 || ^13.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.