It has a clear GPL license and a matching repository owned by an organization. The focused package is easy to identify and document, but its maintenance evidence is too old to support a dependable long-term dependency.
42%
Total Score
50
75
50
The package has had no release in nearly five years, and there were no releases in the last 12 months. This is strong evidence of abandonment risk for a package developers may need to keep compatible.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the long release gap. No provided signal shows compensating maintenance activity.
The repository has no security policy, which is a transparency gap for reporting vulnerabilities. The package is small and has no provided evidence of active security-sensitive maintenance to compensate for that gap.
Version v0.5.0 is not marked as a prerelease, but the 0.x major version indicates an API that may still change before a stable 1.0 release. This adds a modest compatibility concern rather than indicating abandonment by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
helhum/typo3-console Version ^7.0 | — | — |
typo3/cms-composer-installers Version ^3.0 || ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.