The repository matches the package and uses Composer, and the package has no install-time scripts. Its declared LGPL-3.0+ conflicts with the repository's detected GPL-2.0, requiring licensing clarification.
38%
Total Score
0
71
50
The latest release was in August 2020, with no releases in the last six years despite five releases overall. This strongly indicates abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and providing no evidence of ongoing maintenance.
The manifest declares LGPL-3.0+, but the repository license file is detected as GPL-2.0. This mismatch creates a material licensing uncertainty for adopters.
Composer is used as a build tool, which is appropriate for this PHP package, but no security-scanning tooling is present. The missing scanning is a modest hygiene concern.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a transparency gap, though it is less significant than the lack of maintenance activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version >=9.5.0 | — | — |
typo3/cms-frontend Version >9.5.0 | — | — |
symfony/dom-crawler Version ^4.3 | — | — |
typo3/cms-scheduler Version >=9.5.0 | — | — |
symfony/css-selector Version ^4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.