This is a mature, actively maintained and stable TYPO3 package with 270 releases over approximately 9 years, 40 releases in the last 12 months, a current stable major version, and no registry deprecation. The linked organization-owned repository is active, has 48 commits from 13 maintainers in the last 3 months, and shows healthy contributor distribution; the package also has clear licensing, a substantial file tree, repository-backed tests, and no install-time lifecycle scripts. The main reservations are the absence of a repository security policy and security-scanning tooling, plus no recent issue or pull-request activity, although these are outweighed by the strong release and commit history.
92%
Total Score
100
100
94
90
Composer build tooling is present, but no security-scanning tools were detected. This is a hygiene gap, though it is partly offset by the repository's active multi-contributor maintenance.
No repository security policy was detected, reducing transparency about vulnerability reporting and response procedures. This is a genuine but non-severe supply-chain hygiene concern.
| Title | Versions | Severity |
|---|---|---|
CVE-2016-5091 typo3/cms-extbase is vulnerable to Security Vulnerability in versions 0.0.0 - 6.2.24, 7.0 - 7.6.8 and 8.1.1 - 8.1.1. | 0.0.0 - 6.2.247.0 - 7.6.88.1.1 - 8.1.1 | High |
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version 14.3.7 | — | — |
symfony/validator Version ^7.4.8 | — | — |
doctrine/instantiator Version ^1.5 || ^2.0 | — | — |
phpstan/phpdoc-parser Version ^2.1 | — | — |
symfony/property-info Version ^7.4.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.