It has a clear MIT license, README, tests, changelog, and an organization-backed repository. Security scanning is absent, and the single registry maintainer leaves limited visible ownership.
58%
Total Score
50
100
83
50
There were no commits and no active maintainers in the last 3 months, consistent with the long gap since the last release. This is direct evidence of weak current maintenance.
The package runs a post-autoload-dump lifecycle script during installation. A lifecycle script adds execution complexity and deserves caution because its behavior is not described by this signal.
The package has had no release in about 3 years and 6 months, despite five releases since 2019. This indicates substantially slowed maintenance for a dependency intended to track its ecosystem.
Eight issues remain open, with no new or closed issues and no pull-request activity in the last month. This suggests limited issue maintenance, though the short observation window prevents treating it as abandonment by itself.
The repository has only 1 star and no forks, so there is little visible community adoption or outside validation. Popularity is supporting evidence, making this a caution rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
b13/picture Version ^1.3 | — | — |
t3v/t3v_core Version dev-develop | — | — |
fluidtypo3/vhs Version ^6.1 | — | — |
typo3/cms-core Version ^10.4.36 || ^11.5.25 | — | — |
t3v/t3v_translations Version dev-develop | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.