Usable with caveats: the release is current, stable, licensed, and backed by a matching active repository, but maintenance is concentrated in one contributor and releases are relatively infrequent. The repository also has no security policy or automated security scanning.
68%
Total Score
60
100
83
83
One registry publishing maintainer is listed. This is a limited publishing base, and the repository is not shown as organization-owned, so there is little redundancy if that maintainer becomes unavailable.
The repository is owned by a user account rather than an organization, so the narrow maintainer base is not visibly compensated by clear organizational backing.
The package has existed for about 4 years and has 8 releases, but only 2 releases in the last 12 months with a median interval of about 228 days indicates a deliberately slow maintenance cadence.
All 3 recent commits came from one contributor, so maintenance depends heavily on a single active person and could be vulnerable to interruption.
The repository received 3 commits in the last 3 months, showing some ongoing maintenance, although the volume is modest for a production dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.