A lightweight TYPO3 API middleware providing a clean, Extbase-free way to define REST-style endpoints under /api/* paths. Includes CSRF protection, frontend authentication support, and allows endpoint access from Fluid without plugins or TypoScript. Ideal for lean SPA-like applications, HTML-over-the-wire workflows, or lightweight headless-style integrations without a frontend build pipeline.
60%
Total Score
caution
Usable with caveats: no recent commits and inconsistent GPL/MIT licensing lower confidence in this release.
A GPL-2.0-or-later license is declared, but the artifact license file is identified as MIT. The release is licensed, yet the mismatch creates material uncertainty about applicable terms.
The repository recorded zero commits and zero active maintainers during the last three months. Because the package is still under a year old, this is a meaningful maintenance concern rather than evidence of abandonment by itself.
Composer is used as the build tool, but no security-scanning tool is detected. The missing scanner is a hygiene gap, not a standalone dependency blocker.
The repository has no published security policy, leaving reporting and response expectations unclear for a package that handles API and authentication-related functionality.
No GitHub Actions workflows were present, so there are no workflow findings or unpinned actions to assess. This provides no CI or automated security evidence, but it is not a workflow vulnerability.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 || ^14.0 | — | — |
typo3/cms-lowlevel Version ^13.4 || ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.