Usable with caveats: the package is licensed, clearly documented, correctly linked to its repository, and has a recent release with notes. However, there have been no releases in nearly two years and no commits or issue activity in the last three months, indicating reduced maintenance momentum.
62%
Total Score
50
88
75
Only one registry account has publishing access, creating a thin publishing base. The linked repository is user-owned rather than organization-backed, and the recent inactivity provides no strong compensating evidence.
The repository owner is an individual user, not an organization, so there is no organizational backing to offset the single-maintainer and low-activity concerns. The repository nevertheless directly corresponds to the package.
The package has 13 releases since January 2023, but none in the last 12 months; its latest release was published in December 2024, nearly two years before this assessment. This materially lowers confidence in ongoing maintenance.
The repository had zero commits and zero active maintainers during the last three months. Combined with no registry releases in the last year, this indicates a meaningful slowdown in maintenance.
There were no new or closed issues and no merged pull requests in the last month, while nine issues remain open. This suggests limited recent responsiveness, though the short observation window prevents treating it as abandonment by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 | — | — |
symfony/console Version >=7.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
typo3/cms-extbase Version ^13.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.