The release is stable and documented, with a clear license and organizational ownership. Dependence on it carries substantial abandonment risk; choose an actively maintained alternative.
15%
Total Score
75
58
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on this release.
The linked source repository is archived, even though it was pushed on December 8, 2025. An archived repository substantially reduces confidence in future fixes and compatibility work.
The package has 27 releases since 2019, but only one release in the last 12 months. Its historical activity is positive, while the recent cadence is thin.
The repository recorded zero commits and zero active maintainers during the last 3 months. This reinforces the abandonment concern, despite the relatively recent release and push.
| Title | Versions | Severity |
|---|---|---|
CVE-2022-33157 subhh/libconnect is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 7.0.8 and 8.0.0 - 8.1.0. | 0.0.0 - 7.0.88.0.0 - 8.1.0 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.