The repository has no security policy, and its README does not identify the package, though organizational ownership and a clear license provide some reassurance. Its small dependency surface and documentation make the code easier to inspect, but do not offset the maintenance uncertainty.
43%
Total Score
67
100
64
83
The package has had no releases in about six years, despite 34 releases overall; that long gap is a substantial abandonment concern.
There were zero commits and zero active maintainers in the last three months, consistent with the broader indication that development has stopped.
The repository neither matches the full package name nor mentions it in the README, so package ownership is less transparent; its TYPO3 organization context partly reduces that concern.
Composer is used for the build, but no security scanning tools were detected; the missing scanning is a modest hygiene gap rather than evidence of abandonment by itself.
The linked repository has no security policy, leaving disclosure and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version 9.3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.