The source repository remains active under an organization, but activity is minimal and concentrated in one contributor. Open work is not moving, and the project lacks a security policy and pins none of its workflow actions.
20%
Total Score
63
25
50
Packagist marks the entire package as abandoned and names wapplersystems/a21glossary as its replacement. This is a severe adoption risk for a new dependency.
The package has had no releases in the last 12 months, despite 10 releases overall. The repository's later push provides some evidence of ongoing work, but does not offset the missing release cadence.
All recent commits come from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown in this period.
Only 1 commit was recorded in the last 3 months, from 1 active maintainer. This indicates very limited recent maintenance capacity.
The repository has 12 open issues and 7 open pull requests, with no new or closed items in the last month. That combination suggests unresolved maintenance backlog.
| Title | Versions | Severity |
|---|---|---|
CVE-2009-4803 svewap/a21glossary is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 0.4.10. | 0.0.0 - 0.4.10 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4.0 | — | — |
typo3/cms-frontend Version ^13.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.