The source remains linked and well-documented, with tests, a changelog, and a matching repository. Workflow references are all unpinned, and a high-confidence release-workflow template issue plus absent security scanning add maintenance and publishing risk.
58%
Total Score
50
50
81
50
The latest registry release was in May 2020, with no releases in the last 12 months despite the package being about eight years old. This is a substantial sign of a stale published release line.
The repository recorded no commits and no active maintainers in the last three months. This weakens confidence that bugs or compatibility problems will be addressed promptly.
The extension declares 17 runtime dependencies, including several TYPO3 components and platform extensions. This is a relatively broad compatibility surface for an older extension and can increase upgrade and maintenance burden.
A post-autoload-dump install script runs during Composer operations. This adds some execution-time supply-chain exposure, although the signal provides no evidence that the script is malicious or unusually broad.
There are 14 open issues and 3 open pull requests, but no issues or pull requests were created or closed in the last month. The backlog and lack of recent resolution suggest limited active maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dmk/mkforms Version ^9.5.2 | — | — |
typo3/cms-core Version ^7.6.23 || ^8.7.9 | — | — |
typo3/cms-lang Version ^7.6 || ^8.7 | — | — |
digedag/rn-base Version ^1.10.5 | — | — |
typo3/cms-fluid Version ^7.6 || ^8.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.