A clear license, README, repository tests, and organization ownership improve transparency. The small dependency footprint and absent install scripts limit operational exposure.
58%
Total Score
67
100
83
83
The package has 15 releases since February 2020, but none in the last 12 months and its latest recorded release was about 20 months ago, indicating a meaningful maintenance gap.
The repository had no commits and no active maintainers in the last 3 months, reinforcing the concern about stalled maintenance.
There were three open issues and no issues or pull requests changed in the last month, providing additional evidence of limited current activity.
The linked repository has no security policy, which reduces transparency for reporting and handling vulnerabilities, though it is not evidence of a security defect.
The release is marked stable and not a prerelease, but the collected latest version is 12.4 while the assessed release is 13.4, creating a material version-data inconsistency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-backend Version ^13.4 | — | — |
typo3/cms-frontend Version ^13.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.