The project has a clear README, an MIT license, and a repository that matches the package. Its 21 runtime dependencies and install-time scripts increase upkeep, while the repository lacks security scanning. The long period without a new release creates substantial abandonment risk for a current dependency.
38%
Total Score
50
71
50
The package has had no release in more than 7 years, with 0 releases in the last 12 months and only 4 releases overall. This is strong evidence of abandonment risk for a current dependency.
The package declares 21 runtime dependencies and no development dependencies, creating a substantial maintenance and compatibility surface for an outdated project skeleton.
The package runs post-autoload-dump, post-create-project-cmd, and post-install-cmd scripts. These are relevant to a Composer project template but increase install-time complexity and upkeep requirements.
The repository has 1 star, 0 forks, and 1 watcher, providing little supporting evidence of community adoption or external maintenance capacity.
The linked repository has no security policy or security-policy file. This is a transparency gap, although it is less significant than the project's stale release history.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-seo Version ^9.5 | — | — |
typo3/minimal Version ^9.5 | — | — |
phifa/template Version dev-master | — | — |
typo3/cms-form Version ^9.5 | — | — |
typo3/cms-info Version ^9.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.