Healthy and reasonable to adopt, with some maintenance and security-hygiene caveats. It has a current stable release, regular recent publishing, organizational backing, and a matching source repository, but recent work is concentrated in one contributor and the repository lacks a security policy.
78%
Total Score
75
100
88
70
A post-autoload-dump lifecycle script runs during installation. This is not inherently unsafe, but it adds installation behavior that should be reviewed before adoption.
A substantial README and changelog are present, and GitHub Releases are used. Tests are absent in both the artifact and repository, which is a modest verification gap for this extension.
All recent commits came from one contributor, creating concentration risk. This is partly mitigated because the repository is owned by an organization that can potentially hand maintenance off.
Only 1 commit was recorded in the last 3 months, showing limited direct development activity; the recent release and merged pull requests provide some compensating evidence.
Composer build tooling is present, but no security scanning tools are configured, leaving a security-process gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12 || ^13.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.