The package has clear documentation, a recent release, and a matching source repository. Its license texts disagree, while maintenance depends on one contributor with only one commit in the last three months.
62%
Total Score
50
90
50
The manifest declares GPL-2.0-or-later, while the artifact license file is detected as GPL-3.0; although license files exist in both package and repository, the mismatch requires clarification.
All recent commits came from one contributor, leaving maintenance highly dependent on a single person and increasing continuity risk.
The repository recorded one commit in the last three months, indicating limited recent development activity, though the recent release provides some compensating evidence.
The repository has no security policy. This is a modest transparency gap for a small extension, but it is not severe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version >=12.4.0 < 14.3.99 | — | — |
typo3/cms-rte-ckeditor Version >=12.4.0 < 14.3.99 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.