The package is clearly identified, licensed, tested, and backed by an organization with a recent release. Maintenance activity is quiet, and the repository has no security policy or scanning, so pinning this version deserves some caution.
67%
Total Score
75
100
89
83
The package has existed for about 4 years and 11 months, with 7 releases and 1 release in the last 12 months. The long median interval of about 253 days indicates a slow cadence, but the release on June 11, 2026 shows it is not abandoned.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Although the recent release and push show some activity, the lack of ongoing commits is a maintenance caution.
Composer is used as a build tool, but no security-scanning tools were detected. The missing scanning is a modest transparency and maintenance gap, not evidence of a defect in the release.
The repository has no security policy. For a small TYPO3 module this is a limited process gap, but it leaves vulnerability reporting expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4.0 || ^13.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.