The package is small and well-scoped, with a README, a declared GPL license, and only two runtime dependencies. Its repository has no tests, changelog, or security policy, limiting transparency and review capacity.
64%
Total Score
50
100
94
50
One registry maintainer publishes the package, and the repository is owned by an individual rather than an organization. This leaves a thin publishing and continuity base if that maintainer becomes unavailable.
There were no commits and no active maintainers in the last three months. The recent release provides some compensation, but the current lack of source activity raises maintenance risk.
The repository has one open issue and two open pull requests, with no issues or pull requests closed in the last month. The small backlog is not severe, but it suggests limited visible follow-through.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tool was detected. The missing scanning is a modest process gap rather than a direct health failure.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a transparency gap for a backend extension, though it is not evidence of a vulnerability.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 | — | — |
friendsoftypo3/fontawesome-provider Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.