The package includes clear installation guidance, a license, and a repository that matches its name. Its short history and lack of a security policy leave less evidence of long-term support, while organizational ownership partly offsets the single active contributor.
70%
Total Score
83
93
67
The package is only 35 days old with two releases published within minutes of each other, so there is limited evidence of sustained maintenance or release discipline.
All five recent commits came from one contributor, creating a real handoff risk. Organizational ownership provides some maintenance capacity, but no second active contributor is shown.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
No GitHub Actions workflows were present, so the audit found no workflow hazards; this also provides no evidence of automated build or security checks.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4.34 || ^14.3.6 | — | — |
typo3/cms-fluid Version ^13.4.34 || ^14.3.6 | — | — |
typo3fluid/fluid Version ^4.6.1 || ^5.3.1 | — | — |
typo3/cms-felogin Version ^13.4.34 || ^14.3.6 | — | — |
typo3/cms-frontend Version ^13.4.34 || ^14.3.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.