The small scope, clear README, and limited dependencies keep integration straightforward. Maintenance capacity looks thin, so pin 2.1.0 and reassess before upgrading.
63%
Total Score
50
100
94
50
Only one registry account has publish access. This is a limited publishing base, although the linked repository and recent release provide some compensating evidence.
There were zero commits and zero active maintainers in the last three months. The recent release partly offsets this, but the current maintenance signal is thin.
Two issues and two pull requests remain open, with no new or closed items in the last month. This suggests limited recent project activity, though the small package scope makes the evidence moderate rather than severe.
Composer is used for the build, but no security-scanning tool was detected. That leaves a repository hygiene gap for a package distributed as a dependency.
The repository has no security policy. This weakens transparency around vulnerability reporting and maintainer response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 || ^13.4 | — | — |
typo3/cms-backend Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.