The package includes a clear README, a license, and a small dependency set. The linked repository is not archived and was pushed recently, but that does not offset the release being marked abandoned.
28%
Total Score
50
100
64
83
Packagist marks the entire package as abandoned and points to the same package as its replacement, leaving no clear migration target and materially increasing adoption risk.
The latest registry release was published in May 2023, with no releases in the last 12 months; by collection time, that is more than three years without a new release.
The repository shows no commits and no active maintainers in the last three months, which weakens evidence of ongoing maintenance despite a later recorded push in repository metadata.
Composer is used for the build, but no security-scanning tooling is present; the missing scan is a modest repository hygiene gap rather than evidence of abandonment by itself.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities, though this is less significant than the package's abandonment status.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version >=11.5.0,<11.5.99 | — | — |
typo3/cms-frontend Version >=11.5.0,<11.5.99 | — | — |
typo3/cms-fluid-styled-content Version >=11.5.0,<11.5.99 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.