The package has a clear GPL-2.0+ declaration and an organization-owned repository, providing useful ownership context. Its long period without releases or commits makes future compatibility and support uncertain; pinning this version is prudent.
58%
Total Score
83
100
63
75
The artifact has no readme, tests, or changelog, and the repository reports the same. This reduces transparency for consumers, although the compact TYPO3 extension tree makes missing published tests and changelog less concerning than missing maintenance activity.
The latest release was in April 2024, with no releases in the following 12 months despite 17 releases since 2018; this points to materially slowed maintenance.
There were no commits and no active maintainers in the last three months, consistent with the release gap and raising abandonment and compatibility risks.
The repository name does not exactly match the package name, and no README mention was collected. Because the repository is organization-owned and the mismatch can reflect naming conventions, this is only a modest identity-transparency concern.
The repository has no stars or forks and one watcher. This is weak supporting evidence, but popularity alone does not determine the health of a small extension.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ~10.4.0 | — | — |
madj2k/t3-core-extended Version ~10.4.0 || ~11.5.0 || ~12.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.