The package has tests, a clear license, Composer tooling, and Dependabot coverage. Recent development has paused for three months, releases are infrequent, and the linked repository does not clearly mention this package; its organization backing partly offsets that concern.
62%
Total Score
75
100
81
75
No commits and no active maintainers were recorded in the last three months. This is the strongest maintenance concern, though the repository was pushed recently and the package has recent releases.
The package is about 18 months old with 16 releases, but only two releases arrived in the last 12 months and the median interval is less than one day, indicating an uneven cadence.
The repository name does not match the package name and its README does not mention the package, creating uncertainty about the package-to-source link. Organization backing and the matching TYPO3 kickstarter contents partly reduce, but do not remove, that concern.
No security policy is present. This is a transparency gap for a maintained development tool, but it is not severe enough to make the release unfit by itself.
Version 0.4.0 is not a stable major release, so its API and behavior may still change. It is not marked as a prerelease, which provides some compensating stability.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14 | — | — |
friendsofphp/php-cs-fixer Version ^3.49 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.