This is a mature, actively maintained TYPO3 component with a long release history, frequent recent releases, stable versioning, an unarchived organization-backed repository, and five active contributors with balanced commit activity. The package is licensed, has no install-time lifecycle scripts, and its missing packaged tests are compensated by repository tests. The main reservations are the absence of a repository security policy and security-scanning tooling, plus no recent issue or pull-request activity; these are transparency and process gaps rather than evidence of abandonment. Overall, it appears suitable to depend on when used within the compatible TYPO3 stack.
88%
Total Score
90
100
94
90
There were no new or closed issues or pull requests in the last month, and issue totals are unavailable; this is a limited activity signal, but it is outweighed by recent releases and commits.
Composer build tooling is present, but no security-scanning tools were detected, leaving a process gap in repository security hygiene.
The repository has no security policy, reducing transparency about vulnerability reporting and response procedures.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version 14.3.7 | — | — |
typo3/cms-fluid Version 14.3.7 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
typo3fluid/fluid Version ^5.3.2 | — | — |
typo3/cms-backend Version 14.3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.