This is a mature, actively released TYPO3 extension with 198 releases over more than six years, 40 releases in the last 12 months, a stable non-prerelease version, and no registry deprecation. The linked organization-owned repository is not archived, was pushed recently, and shows activity from five contributors, which supports maintenance capacity despite the package's low public popularity. The artifact is licensed, has substantial source and documentation, uses a focused runtime dependency set, and has no install-time lifecycle scripts. The main gaps are the absence of a repository security policy and security-scanning tooling, plus no changelog detected; these reduce transparency and security-process confidence but are not sufficient to make the release unfit to depend on.
88%
Total Score
90
100
89
90
No new or closed issues or pull requests were recorded in the last month, while total issue and pull-request counts are unknown; this provides little recent collaboration evidence but is outweighed by release and commit activity.
The repository has only 8 stars, 1 fork, and 1 watcher, which is limited popularity evidence; this is a minor concern but not decisive for an organization-owned component with strong release activity.
Composer build tooling is present, but no security-scanning tools were detected; the missing scanning process is a modest security-hygiene gap.
The linked repository has no security policy, reducing transparency about vulnerability reporting and response procedures.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-55920 typo3/cms-dashboard is vulnerable to Cross-Site Request Forgery (CSRF) in versions 10.0.0 - 10.4.47, 11.0.0 - 11.5.41, 12.0.0 - 12.4.24 and 13.0.0 - 13.4.2. | 10.0.0 - 10.4.4711.0.0 - 11.5.4112.0.0 - 12.4.24 +1 more | Medium |
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version 14.3.7 | — | — |
typo3/cms-fluid Version 14.3.7 | — | — |
typo3/cms-backend Version 14.3.7 | — | — |
typo3/cms-extbase Version 14.3.7 | — | — |
typo3/cms-frontend Version 14.3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.