The package has a clear README, release notes, stable version, and organization backing. Security policy and scanning are absent, and the repository recorded no commits in the last three months.
68%
Total Score
75
100
81
83
Only two releases appeared over nearly a year, with the latest about 20 days after the first. This is a young package with limited release history, so maintenance maturity remains unproven.
No commits and no active maintainers were recorded during the last three months. This is a meaningful maintenance warning, although the package is still relatively young.
The repository name matches the package, which supports the link, but the README does not mention the package name explicitly. That creates a minor ownership and packaging-transparency concern.
Composer is used for builds, but no security scanning tools were detected. The missing scanning reduces assurance around ongoing maintenance hygiene.
The repository has no security policy. This limits transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.