The package is clearly licensed and its repository matches the package, which improves transparency. Its 0.x status, sparse release history, and no recent commits leave maintenance capacity uncertain; no security policy is published.
61%
Total Score
75
100
75
83
The manifest declares GPL-3.0-or-later and the artifact and repository both contain license files. The detected GPL-3.0 text is narrower than the manifest declaration, so the exact licensing position deserves confirmation.
The package has six releases over about three years, with one release in the last 12 months and a median interval of about 143 days. This indicates a small and somewhat slow release cadence rather than abandonment by itself.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance warning, although the recent repository push and release history provide some counterweight.
Composer is used for the build, which fits the package ecosystem. No security scanning tools are configured, leaving a modest repository hygiene gap.
The repository has no security policy. For a package integrated into TYPO3 applications, this reduces transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version >=11.5 <15 || 15.*.*@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.