The project has no tests or security scanning, and publishing depends on one registry maintainer. Its README says the extension is not function-ready and is intended as an idea for building a custom implementation.
34%
Total Score
25
100
64
50
This is the only release, published about 1 year 9 months ago, with no releases in the last 12 months. That provides little evidence of ongoing maintenance for a migration tool.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, reinforcing the lack of recent release activity and increasing abandonment risk.
Only one account has registry publishing access. A single maintainer is a modest resilience concern for an independently owned project, especially when recent repository activity is absent.
The package includes a README, but it explicitly says the extension is not function-ready and is intended as an idea for building a custom implementation. Missing tests are normal for published artifacts, but the README materially limits confidence for a migration dependency.
The repository name does not match the package name, and its README does not mention the package. Although name differences can occur in related projects, both gaps make package ownership and maintenance harder to verify.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^10.4 || ^11.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.