This release appears healthy and suitable for dependency use: it has a mature release history with 62 releases over roughly 2 years and 27 releases in the last 12 months, is actively maintained, is not deprecated or archived, and provides strong package documentation, tests, changelog coverage, licensing, and a coherent source tree. The main concerns are a highly concentrated commit profile, absence of repository security scanning and a security policy, and a workflow without top-level token permissions; these are meaningful hygiene gaps but are partly offset by active organizational backing, three active contributors, recent issue and pull-request resolution, and a workflow with no detected dangerous patterns.
86%
Total Score
90
100
94
80
The top contributor made about 90.4% of the 83 recent commits, creating a meaningful concentration and continuity risk. Two additional contributors remain active and organizational backing partly mitigates the risk, so the net impact is caution rather than danger.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a repository hygiene gap, though it does not by itself indicate abandonment.
No security policy was found in the repository, reducing transparency about vulnerability reporting and response procedures.
The one analyzed workflow lacks top-level token permissions. Although no top-level write permissions were detected, explicitly constraining permissions would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 || ^13.4 || ^14.0 | — | — |
deeplcom/deepl-php Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.