The package includes a clear README, a license, a matching source repository, and a modest dependency set. Its single release and no commits in the last three months leave ongoing maintenance unproven, while the license-text mismatch and absent security policy add smaller concerns.
62%
Total Score
50
100
81
75
A license file is present and the repository also contains one, but the detected GPL-2.0 text does not exactly match the declared GPL-2.0-or-later license, creating a minor licensing clarity concern.
The package is 159 days old and has only one release, so there is not yet enough release history to demonstrate sustained maintenance.
There were zero commits and zero active maintainers in the last three months, which is concerning for a package whose only release was about five months ago.
The repository uses Composer build tooling, but no security scanning tool was detected; this is a modest transparency and hygiene gap.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 || ^12.4 | — | — |
symfony/console Version ^6.4 || ^7.0 | — | — |
typo3/cms-fluid Version ^13.4 || ^12.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.