Package Health

typo3/cms-core

This is a mature, actively maintained TYPO3 core release with a long release history, frequent recent releases, a non-archived organization-backed repository, substantial recent commit activity, and a broad contributor base. Licensing is explicit and supported by a license file, lifecycle scripts are absent, and the repository clearly references the package despite the monorepo name mismatch. The main reservations are the absence of a repository security policy and security-scanning tooling, plus the package's large runtime dependency surface; missing packaged tests and changelog are less concerning because the repository contains tests and the package is a large core component. Overall, it appears safe to depend on from a maintenance and supply-chain transparency perspective, subject to normal review of its many transitive dependencies.

Latest v14.3.7PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Are you affected? Scan for Free

Health Score Breakdown

Dependency profilecaution

The release declares 63 runtime dependencies, including substantial Symfony, Doctrine, and HTTP-related components; this is understandable for a framework core but increases transitive maintenance and upgrade exposure.

Package scaffoldingcaution

The artifact includes a README but no packaged tests or changelog; the missing packaged tests are compensated by repository tests, while the absent changelog is a minor transparency gap for a mature package.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected; the missing scanning capability is a supply-chain hygiene gap, though not evidence of abandonment.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting and coordinated-disclosure practices less transparent for a security-sensitive core framework.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-11607
typo3/cms-core is vulnerable to Missing Authorization in versions 0.0.0 - 10.4.57, 11.0.0 - 11.5.51, 12.0.0 - 12.4.46, 13.0.0 - 13.4.31 and 14.0.0 - 14.3.3.
0.0.0 - 10.4.5711.0.0 - 11.5.5112.0.0 - 12.4.46 +2 more
High
CVE-2026-47349
typo3/cms-core is vulnerable to Missing Authorization in versions 0.0.0 - 10.4.57, 11.0.0 - 11.5.51, 12.0.0 - 12.4.46, 13.0.0 - 13.4.31 and 14.0.0 - 14.3.3.
0.0.0 - 10.4.5711.0.0 - 11.5.5112.0.0 - 12.4.46 +2 more
Medium
CVE-2026-47347
typo3/cms-core is vulnerable to URL Redirection to Untrusted Site ('Open Redirect') in versions 0.0.0 - 10.4.57, 11.0.0 - 11.5.51, 12.0.0 - 12.4.46, 13.0.0 - 13.4.31 and 14.0.0 - 14.3.3.
0.0.0 - 10.4.5711.0.0 - 11.5.5112.0.0 - 12.4.46 +2 more
Medium
CVE-2026-47343
typo3/cms-core is vulnerable to Missing Authorization in versions 0.0.0 - 10.4.57, 11.0.0 - 11.5.51, 12.0.0 - 12.4.46, 13.0.0 - 13.4.31 and 14.0.0 - 14.3.3.
0.0.0 - 10.4.5711.0.0 - 11.5.5112.0.0 - 12.4.46 +2 more
High
CVE-2026-49741
typo3/cms-core is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 14.0.0 - 14.3.3.
14.0.0 - 14.3.3
High

Package versions

Maintainers

TYPO3 Core Team

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0.1
psr/clock
Version ^1.0
symfony/uid
Version ^7.4.8
symfony/mime
Version ^7.4.12
symfony/yaml
Version ^7.4.12

Weekly Downloads

Info

Last Published
16 days ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform