The release includes notes, a license, and a focused dependency profile. The source project is archived, with no commits in the last three months and no releases since October 2017; its missing security policy adds little maintenance confidence.
32%
Total Score
50
100
69
83
The package has only four releases and none in the last 12 months; its latest release was October 28, 2017. This long release gap substantially raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months. This confirms there is no recent maintenance activity to offset the old release history.
The linked repository is archived, with its last push on February 22, 2022. An archived source project is a severe abandonment concern for a package dependency.
The repository uses Composer, but no security-scanning tools are reported. The build tooling is appropriate, while the missing scanning is a minor hygiene gap.
The repository has no security policy. This weakens transparency and vulnerability-reporting readiness, although it is secondary to the archived project and absent recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms Version >=7.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.