The package includes useful documentation, a changelog, a matching repository reference, and no install-time scripts. Its beta status, tiny user base, absent security policy, and minimal release history leave substantial maintenance risk.
38%
Total Score
50
69
83
Only two releases were published, both around six years ago, with no release in the last 12 months. This strongly suggests the package is no longer actively maintained.
The registry namespace and repository owner match, and the repository is owned by a user account rather than an organization. This offers limited backing evidence but does not imply the project is unaffiliated.
The repository has only 1 star, 0 forks, and 1 watcher, providing little evidence of broad community review or adoption. Popularity is supporting evidence, so this is a modest concern rather than a verdict alone.
Composer is used for builds, but no security scanning tools are reported. For a small package this is a hygiene gap, though it is less significant than the lack of recent releases.
No repository security policy is present. This reduces transparency about vulnerability reporting and handling, adding a maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version >=9.5.0 <=9.5.99||>=10.0.0 <10.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.