The package has focused documentation, a matching repository, and a small dependency surface. It lacks tests and a security policy, so future compatibility and security response are less visible.
58%
Total Score
25
100
89
75
There were no commits and no active maintainers in the last three months. Combined with the old latest registry release, this is a meaningful abandonment and compatibility concern.
One registry account has publish access. Because the repository owner is an individual rather than an organization, the narrow maintainer base modestly increases continuity risk.
The package has five releases over about 6 years and no release in the last 12 months; the latest release was in August 2023. This indicates materially slowed maintenance for a production extension.
The repository uses Composer for builds, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance weakness, not evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This matters for an extension integrated into a CMS application.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.