Clear licensing, a substantial README, and a small dependency set reduce integration friction. The repository has no security policy, so security-reporting expectations are less clear.
74%
Total Score
67
100
88
75
The package has existed for about 9 years with 34 releases and a release in the past month, but only one release in the last 12 months indicates a slower recent cadence.
All recent commits came from one contributor. The organization-owned repository provides some handoff capacity, but no second active contributor is evidenced.
Only one commit from one active maintainer was recorded in the last three months, which shows recent activity but limited ongoing maintenance capacity.
Composer is used for builds, but no security scanning tool is configured, leaving automated security coverage unshown.
The repository has no security policy, so its process for receiving and disclosing vulnerability reports is not documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^11 || ^12 || ^13 || ^14 | — | — |
typo3/cms-fluid Version ^11 || ^12 || ^13 || ^14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.